Re: [PATCH v1 2/2] Input: sur40 - keep device state alive until the video node is released

From: Hans Verkuil

Date: Wed Sep 30 2026 - 04:10:27 EST


On 20/09/2026 13:39, Nguyen Ngoc Thang wrote:
> sur40_disconnect() frees the sur40_state, which embeds the video_device,
> the v4l2_device and the vb2_queue, while a video node may still be open.
> Closing that file afterwards touches freed memory:
>
> BUG: KASAN: slab-use-after-free in vb2_core_queue_release+0x12d/0x150
> Read of size 4 at addr ffff888066fa8aa8 by task v4l_id/28733
> vb2_core_queue_release+0x12d/0x150
> vb2_fop_release+0x16e/0x200
> v4l2_release+0x22c/0x350
> __fput+0x418/0xa50
> Freed by task 16811:
> kfree+0x1c5/0x650
> sur40_disconnect+0xaf/0x140
>
> Give the v4l2_device a release callback that frees the bulk buffer and
> the state, and drop the disconnect path's own reference with
> v4l2_device_put(). The last closer of the node then does the freeing.
> The probe error paths never open the node and keep freeing directly.
>
> Reported-by: syzbot+eb4706daf505f9c4b547@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=eb4706daf505f9c4b547
> Fixes: e831cd251fb9 ("[media] add raw video stream support for Samsung SUR40")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@xxxxxxxxx>

Reviewed-by: Hans Verkuil <hverkuil+cisco@xxxxxxxxxx>

Regards,

Hans

> ---
> drivers/input/touchscreen/sur40.c | 15 ++++++++++++---
> 1 file changed, 12 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/input/touchscreen/sur40.c b/drivers/input/touchscreen/sur40.c
> index 7020bcf9b81a..efd4fe557cef 100644
> --- a/drivers/input/touchscreen/sur40.c
> +++ b/drivers/input/touchscreen/sur40.c
> @@ -648,6 +648,15 @@ static int sur40_input_setup_events(struct input_dev *input_dev)
> }
>
> /* Check candidate USB interface. */
> +/* Runs once the last video node reference is gone. */
> +static void sur40_release(struct v4l2_device *v4l2)
> +{
> + struct sur40_state *sur40 = container_of(v4l2, struct sur40_state, v4l2);
> +
> + kfree(sur40->bulk_in_buffer);
> + kfree(sur40);
> +}
> +
> static int sur40_probe(struct usb_interface *interface,
> const struct usb_device_id *id)
> {
> @@ -733,6 +742,7 @@ static int sur40_probe(struct usb_interface *interface,
> "Unable to register video master device.");
> goto err_free_buffer;
> }
> + sur40->v4l2.release = sur40_release;
>
> /* initialize the lock and subdevice */
> sur40->queue = sur40_queue;
> @@ -831,11 +841,10 @@ static void sur40_disconnect(struct usb_interface *interface)
> video_unregister_device(&sur40->vdev);
> v4l2_device_unregister(&sur40->v4l2);
>
> - kfree(sur40->bulk_in_buffer);
> - kfree(sur40);
> -
> usb_set_intfdata(interface, NULL);
> dev_dbg(&interface->dev, "%s is now disconnected\n", DRIVER_DESC);
> +
> + v4l2_device_put(&sur40->v4l2);
> }
>
> /*