[PATCH] media: dvb-usb-v2: initialize active_fe before registering the demux
From: Sentaro Sakura
Date: Thu Oct 01 2026 - 07:08:13 EST
dvb_usbv2_adapter_init() registers the DVB adapter and demux in
dvb_usbv2_adapter_dvb_init() before dvb_usbv2_adapter_frontend_init()
sets adap->active_fe to -1. Until then active_fe is still 0 from the
zeroed allocation, while adap->fe[] is still empty.
If userspace starts a demux feed in this window, dvb_usb_start_feed()
passes the active_fe == -1 check and calls streaming_ctrl() with
adap->fe[0] == NULL, which crashes in mxl111sf_ep4_streaming_ctrl():
KASAN: null-ptr-deref in range [0x0000000000000308-0x000000000000030f]
RIP: 0010:mxl111sf_ep4_streaming_ctrl+0x2c/0x1a0
Call Trace:
dvb_usb_start_feed+0x57a/0xc70
dmx_ts_feed_start_filtering+0x129/0x220
dvb_dmxdev_filter_start+0x434/0x10d0
dvb_demux_do_ioctl+0x48b/0x540
Before commit e48b2a68617c ("[media] dvb_usb_v2: frontend switching
changes"), start_feed() also rejected feeds when active_fe >=
num_frontends_initialized, which covered this window. That check was
replaced by a plain "active_fe < 0" test, while the -1 initialization
stayed in frontend_init().
Initialize active_fe to -1 when the adapter is set up, before the demux
is registered, so that start_feed() rejects feeds until a frontend is
actually initialized.
Fixes: e48b2a68617c ("[media] dvb_usb_v2: frontend switching changes")
Reported-by: syzbot+3df044e20e6ff1fb3cf5@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=3df044e20e6ff1fb3cf5
Signed-off-by: Sentaro Sakura <s.sakura11500920@xxxxxxxxx>
---
drivers/media/usb/dvb-usb-v2/dvb_usb_core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/media/usb/dvb-usb-v2/dvb_usb_core.c b/drivers/media/usb/dvb-usb-v2/dvb_usb_core.c
index bd86d250433d..b77406a649ec 100644
--- a/drivers/media/usb/dvb-usb-v2/dvb_usb_core.c
+++ b/drivers/media/usb/dvb-usb-v2/dvb_usb_core.c
@@ -760,6 +760,7 @@ static int dvb_usbv2_adapter_init(struct dvb_usb_device *d)
adap = &d->adapter[i];
adap->id = i;
adap->props = &d->props->adapter[i];
+ adap->active_fe = -1;
/* speed - when running at FULL speed we need a HW PID filter */
if (d->udev->speed == USB_SPEED_FULL &&
--
2.53.0