Re: [PATCH v3 2/2] media: v4l2-subdev: Fix NULL pointer dereference in the EXT_CTRLS ioctls
From: Sakari Ailus
Date: Thu Oct 08 2026 - 06:44:16 EST
Hi Nicola,
On Thu, Oct 08, 2026 at 06:26:00AM +0200, Nicola Fiorillo wrote:
> VIDIOC_G_EXT_CTRLS, VIDIOC_S_EXT_CTRLS and VIDIOC_TRY_EXT_CTRLS on a
> sub-device node pass sd->v4l2_dev->mdev to the control framework.
> v4l2_device_unregister_subdev() clears sd->v4l2_dev before it
> unregisters the device node, and nothing serialises the
> video_is_registered() checks in v4l2_ioctl() and subdev_do_ioctl_lock()
> against it: sub-device nodes have no vdev->lock, and unregistration
> would not take it anyway. An EXT_CTRLS ioctl on a file handle opened
> before a driver is unbound can therefore dereference NULL:
Unregistering a sub-device node isn't doable safely currently. Addressing
this properly requires much more than this patch does, and also I'm afraid
this patch isn't part of properly addressing this either.
--
Kind regards,
Sakari Ailus