[PATCH] media: exynos4-is: Fix control handler leak in fimc-isp

From: fengchenguang

Date: Wed Sep 30 2026 - 07:59:18 EST


From: Chenguang Feng <fengchenguang@xxxxxxxxxx>

fimc_isp_subdev_create() initializes the control handler and adds
controls before checking handler->error. On the error path only the
media entity is cleaned up and the handler memory is never freed;
the caller in fimc_is_probe() returns directly, so nothing else
releases it either.

Call v4l2_ctrl_handler_free() in the error path, mirroring
fimc_isp_subdev_destroy().

Fixes: 9a761e436843f ("[media] exynos4-is: Add Exynos4x12 FIMC-IS driver")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Chenguang Feng <fengchenguang@xxxxxxxxxx>
---
drivers/media/platform/samsung/exynos4-is/fimc-isp.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/drivers/media/platform/samsung/exynos4-is/fimc-isp.c b/drivers/media/platform/samsung/exynos4-is/fimc-isp.c
index 3c5d7bee2655..896a1b0952ad 100644
--- a/drivers/media/platform/samsung/exynos4-is/fimc-isp.c
+++ b/drivers/media/platform/samsung/exynos4-is/fimc-isp.c
@@ -760,6 +760,7 @@ int fimc_isp_subdev_create(struct fimc_isp *isp)

if (handler->error) {
media_entity_cleanup(&sd->entity);
+ v4l2_ctrl_handler_free(handler);
return handler->error;
}

--
2.25.1