Re: [PATCH v2] media: imon: fix use-after-free in display_close via dev_dbg

From: Deepanshu Kartikey

Date: Wed Sep 30 2026 - 04:37:51 EST


On Mon, Sep 28, 2026 at 5:55 PM Sean Young <sean@xxxxxxxx> wrote:
>
> On Mon, Sep 28, 2026 at 05:48:26PM +0530, Deepanshu Kartikey wrote:
> > On Mon, Sep 28, 2026 at 5:42 PM Deepanshu Kartikey
> > <kartikey406@xxxxxxxxx> wrote:
> > >
> > > ictx->dev is a raw pointer to the usb_interface's embedded device,
> > > cached in imon_init_intf0() without taking a reference. On
> > > disconnect, usb_disconnect() can drop the last reference on the
> > > interface and free it while a userspace fd for /dev/lcd0 is still
> > > open. When that fd is later closed, display_close() dereferences
> > > the now-freed ictx->dev via dev_dbg(), causing a use-after-free.
> > >
> > > Fix by pinning the device with get_device() when ictx->dev is
> > > assigned, and releasing it with put_device() when ictx is freed.
> > >
> > > Also drop the dev_dbg() in free_imon_context(), which only printed
> > > a debug message and is no longer needed.
> > >
> > > Fixes: 21677cfc562a ("V4L/DVB: ir-core: add imon driver")
> > > Reported-by: syzbot+9bfac891bdd42eb708fc@xxxxxxxxxxxxxxxxxxxxxxxxx
> > > Closes: https://syzkaller.appspot.com/bug?extid=9bfac891bdd42eb708fc
> > > Link: http://lore.kernel.org/all/20260918054851.26083-1-kartikey406@xxxxxxxxx/T/ [v1]
> > > Signed-off-by: Deepanshu Kartikey <kartikey406@xxxxxxxxx>
> > > ---
> > > v2:
> > > - Remove the dev_dbg() in free_imon_context(), as suggested by
> > > Sean Young.
> > > ---
> > > drivers/media/rc/imon.c | 5 +++--
> > > 1 file changed, 3 insertions(+), 2 deletions(-)
> > >
> > > diff --git a/drivers/media/rc/imon.c b/drivers/media/rc/imon.c
> > > index 049a73b5f882..562a70186db4 100644
> > > --- a/drivers/media/rc/imon.c
> > > +++ b/drivers/media/rc/imon.c
> > > @@ -501,7 +501,7 @@ static void free_imon_context(struct imon_context *ictx)
> > > usb_free_urb(ictx->rx_urb_intf1);
> > > kfree_rcu(ictx, rcu);
> > >
> > > - dev_dbg(dev, "%s: iMON context freed\n", __func__);
> > > + put_device(dev);
>
> Why do you need put_device()?
>


yes it is of no use. So, I have removed it and send patch v3.

Thanks

Deepanshu