Re: [PATCH] media: imon: fix use-after-free in display_close via dev_dbg
From: Deepanshu Kartikey
Date: Mon Sep 28 2026 - 08:33:47 EST
On Sat, Sep 26, 2026 at 5:26 PM Sean Young <sean@xxxxxxxx> wrote:
>
> On Fri, Sep 18, 2026 at 11:18:51AM +0530, Deepanshu Kartikey wrote:
> > ictx->dev is a raw pointer to the usb_interface's embedded device,
> > cached in imon_init_intf0() without taking a reference. On
> > disconnect, usb_disconnect() can drop the last reference on the
> > interface and free it while a userspace fd for /dev/lcd0 is still
> > open. When that fd is later closed, display_close() dereferences
> > the now-freed ictx->dev via dev_dbg(), causing a use-after-free.
> >
> > Fix by pinning the device with get_device() when ictx->dev is
> > assigned, and releasing it with put_device() when ictx is freed.
> >
> > Fixes: 21677cfc562a ("V4L/DVB: ir-core: add imon driver")
> > Reported-by: syzbot+9bfac891bdd42eb708fc@xxxxxxxxxxxxxxxxxxxxxxxxx
> > Closes: https://syzkaller.appspot.com/bug?extid=9bfac891bdd42eb708fc
> > Signed-off-by: Deepanshu Kartikey <kartikey406@xxxxxxxxx>
> > ---
> > drivers/media/rc/imon.c | 4 +++-
> > 1 file changed, 3 insertions(+), 1 deletion(-)
> >
> > diff --git a/drivers/media/rc/imon.c b/drivers/media/rc/imon.c
> > index 049a73b5f882..9341dbe03b57 100644
> > --- a/drivers/media/rc/imon.c
> > +++ b/drivers/media/rc/imon.c
> > @@ -502,6 +502,7 @@ static void free_imon_context(struct imon_context *ictx)
> > kfree_rcu(ictx, rcu);
> >
> > dev_dbg(dev, "%s: iMON context freed\n", __func__);
>
> The dev is only referenced in dev_dbg() here.
>
> The debug statement is pretty pointless anyway so why don't we remove
> that instead.
>
>
> Sean
I misunderstood your last message.
The reported crash is in display_close(), and
ictx->dev is also passed to dev_dbg() in display_open() and lcd_write(),
which can run after disconnect. Removing only the dev_dbg() in
free_imon_context() would not fix the bug.
Do you want me to replace dev_dbg from all over the place ?
Thanks