Received: by 2002:a05:6358:7058:b0:131:369:b2a3 with SMTP id 24csp3782839rwp; Sat, 15 Jul 2023 09:15:16 -0700 (PDT) X-Google-Smtp-Source: APBJJlGPc4B93GsiBjXWLMGApu4t5IGN1nG77PKXPknEXUhZgXsInxV39lgzI2tZF5jxmnpRfqJg X-Received: by 2002:a17:906:77d6:b0:993:d54b:3e46 with SMTP id m22-20020a17090677d600b00993d54b3e46mr5422976ejn.0.1689437716263; Sat, 15 Jul 2023 09:15:16 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1689437716; cv=none; d=google.com; s=arc-20160816; b=FY7Ppql56xh8/xsXgWZWO7K1qUVoKMO6rVFnyML3i20O2yK413nD2/4bpOB9+dkHCU P1ZDdQR78muX+x7ov8hpo6RUPK5L9hniPXJe4imYh9AiZoym9tazBxLGWM+JjXQvCMMO wCnHbLhqIMn6+/BHuOLZmkn/tryy6C/BI+FprUDEIENCHLEHV4c8CC6xewv7NT/OcYz5 vXpTAtlq2D8lRAuIT1j26ViwRdbyFdmBu4dsBEbkJKxOllVTxr09aOfw4wiBvhbcXSR+ VvMSVkzIC0+GyMrhoAXTvK7RHvV8rfwwi96C1FieZ8VxwdU6Ubfc6STaLgCkdWwfyI/V yDLA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:cc:to:subject :message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=Wj4Cy8RQ6W/zc3QPSV8hmPb4p0rBodU5v6Z12U3dgao=; fh=iLsyqu1Pu0Q8hTAhBdNXKxsAPeWFtFmikKrLzCiI7pM=; b=iKOjF+J+cu0XJmkZujcI315YRjekNPcafthGMIwuBcPUexXp2fZRmdIabEIPK3IBxk LrPTsVsJR908jYOjnW3CuxVsMSH6pV0ClwYy74MR6qNIXCz7DRimyb6ocsds/dO0XBRj F8iP/y+ANlcLBK8pbFU/nf4yFIYKu//bFocSw5sB83fQbsGeASbgHGl2BcjVX3UH3Ey5 aKaH6kSUVH0sKJFK/zHL6pYlgXTo0jhhXPacNP4+FBM4xOIcwIlVjCG+b7RB2/zFtr4t NrpFydEahcU69ZF8F7G91dw0Sq7cPoUWjKQ3hqryICgZgZJGzPq739xt11BMGdjR7nH0 GL7w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20221208 header.b=f1Yoji6L; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id i7-20020a17090639c700b00988c408ed41si10801887eje.513.2023.07.15.09.14.51; Sat, 15 Jul 2023 09:15:16 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20221208 header.b=f1Yoji6L; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229775AbjGOQIr (ORCPT + 99 others); Sat, 15 Jul 2023 12:08:47 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43184 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229472AbjGOQIq (ORCPT ); Sat, 15 Jul 2023 12:08:46 -0400 Received: from mail-pl1-x636.google.com (mail-pl1-x636.google.com [IPv6:2607:f8b0:4864:20::636]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C1B5B2D51; Sat, 15 Jul 2023 09:08:45 -0700 (PDT) Received: by mail-pl1-x636.google.com with SMTP id d9443c01a7336-1b8a8154f9cso18714415ad.1; Sat, 15 Jul 2023 09:08:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1689437325; x=1692029325; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=Wj4Cy8RQ6W/zc3QPSV8hmPb4p0rBodU5v6Z12U3dgao=; b=f1Yoji6Lk7hLFrGWvVHMB99I94iqNPLf53nN99C+Euf1eko0lDj6+rwlqw+Dgk8UQQ SRpsuRlsVNHD4H3CtBAY6OqSPEqSJZUwFP+cS9hB5oGMHDh1EVrIAUWdGU5BH6VhjFBW /z1yHF+21yYGgNq9TAwrNx1v4HfpVczxiW79BGFcmf51YVbRm8YkB2rC0PG8Wz14mMZc 0CZz2ejtvs3mc6jFez6MjOZAENbTvA1WktKizZDkR7JMqJrAQbPdsIohUFetUtXw+PaF KQoa95Jtgb3QO1zhPcZxPZtw2Jc8U8JccvLv74fIUQ1k70FctgFVnPIiuRT5Ui6YXY5w ivhA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1689437325; x=1692029325; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=Wj4Cy8RQ6W/zc3QPSV8hmPb4p0rBodU5v6Z12U3dgao=; b=IDXezXX+5fsAuzXAeNyV7QwKRoTISnTLuDNNxCKaCecUZXmVJPrDZ2nICAcPl+77hm xREgD8AOKDqIHoUV6cw+92oqddOynyvYXWAaBPFsEfrck2eZU1Ay8hWBGXjRK3kZD5rS 9sfnMNNykrhUo+qSWpn7hrNbHVOd0ITTx03nMbaB59OQCCFittAT+8BGhZ/MSGXN+LGY +VQSSdDRa+Lx0O/pL0qt4zK62tpRwbuQKpQg6nC9Nuevd4JEqByOXcS92bkZ77L/fhQa Vcy0sOvP1knyv+exIXRVc4nlbHASz4WHqmRP+Gs1Wwl9IjCcJDNTdFT0DcdBz7qW5LFd jOeQ== X-Gm-Message-State: ABy/qLaTDxOehF68+R7OkVIpm1l3m4njo0KncreHKKYeAHs2tWLtF2Oi 7YkcNJHiJ/ZLvwqDVga3GcHPxVxoVd0SJeU5mWQ= X-Received: by 2002:a17:902:dac7:b0:1b6:b703:36f8 with SMTP id q7-20020a170902dac700b001b6b70336f8mr8179654plx.25.1689437325128; Sat, 15 Jul 2023 09:08:45 -0700 (PDT) MIME-Version: 1.0 References: <20230707092414.866760-1-zyytlz.wz@163.com> <538096d2-7b24-e1c7-706d-4d4f952d35eb@baylibre.com> In-Reply-To: <538096d2-7b24-e1c7-706d-4d4f952d35eb@baylibre.com> From: Zheng Hacker Date: Sun, 16 Jul 2023 00:08:33 +0800 Message-ID: Subject: Re: [RESEND PATCH v2] media: mtk-jpeg: Fix use after free bug due to uncanceled work To: Alexandre Mergnat Cc: Zheng Wang , Kyrie.Wu@mediatek.com, bin.liu@mediatek.com, mchehab@kernel.org, matthias.bgg@gmail.com, angelogioacchino.delregno@collabora.com, linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org, Irui.Wang@mediatek.com, security@kernel.org, 1395428693sheep@gmail.com, alex000young@gmail.com Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_ENVFROM_END_DIGIT, FREEMAIL_FROM,RCVD_IN_DNSWL_BLOCKED,SPF_HELO_NONE,SPF_PASS, T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi, This issue has not been resolved for a long time. Is there anyone who can h= elp? Best regards, Zheng Alexandre Mergnat =E4=BA=8E2023=E5=B9=B47=E6=9C=887= =E6=97=A5=E5=91=A8=E4=BA=94 22:11=E5=86=99=E9=81=93=EF=BC=9A > > > > On 07/07/2023 11:24, Zheng Wang wrote: > > In mtk_jpeg_probe, &jpeg->job_timeout_work is bound with > > mtk_jpeg_job_timeout_work. Then mtk_jpeg_dec_device_run > > and mtk_jpeg_enc_device_run may be called to start the > > work. > > If we remove the module which will call mtk_jpeg_remove > > to make cleanup, there may be a unfinished work. The > > possible sequence is as follows, which will cause a > > typical UAF bug. > > > > Fix it by canceling the work before cleanup in the mtk_jpeg_remove > > > > CPU0 CPU1 > > > > |mtk_jpeg_job_timeout_work > > mtk_jpeg_remove | > > v4l2_m2m_release | > > kfree(m2m_dev); | > > | > > | v4l2_m2m_get_curr_priv > > | m2m_dev->curr_ctx //use > > Reviewed-by: Alexandre Mergnat > > -- > Regards, > Alexandre