linux/drivers/media/dvb-core
Rituparna Warwatkar 9fa26c971c media: dvb-core: fix feed leak on failed DMX_ADD_PID
dvb_dmxdev_add_pid() allocates a new dmxdev_feed, links it into
filter->feed.ts and, when the filter is already running, immediately
starts the feed.

If starting the feed fails, the newly allocated feed remains on the
list. Subsequent restart and rollback paths may then operate on this
stale entry, leaving feed resources allocated and causing leaks in
drivers that allocate resources from ->start_feed() and release them
from ->stop_feed().

Remove the feed from the list and free it when
dvb_dmxdev_start_feed() fails.

Reported-by: syzbot+e9a1f5e196de6663631b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e9a1f5e196de6663631b
Signed-off-by: Rituparna Warwatkar <rwarwatkar@gmail.com>
Link: https://patch.msgid.link/20260714141059.63582-1-rwarwatkar@gmail.com
Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
Message-ID: <20260714141059.63582-1-rwarwatkar@gmail.com>
2026-07-27 18:00:56 +02:00
..
dmxdev.c media: dvb-core: fix feed leak on failed DMX_ADD_PID 2026-07-27 18:00:56 +02:00
dvb_ca_en50221.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
dvb_demux.c media: dvb-core: use vmalloc_array to simplify code 2025-10-14 15:07:36 +02:00
dvb_frontend.c media: drivers/media/dvb-core: CodeStyle for dvb_frontend_open() 2026-07-10 14:17:56 +02:00
dvb_net.c media: dvb-net: fix OOB access in ULE extension header tables 2026-02-27 10:57:48 +01:00
dvb_ringbuffer.c media: dvb-core: dvb_ringbuffer: Fix various coding style issues 2025-10-14 15:07:36 +02:00
dvb_vb2.c media: dvb-core: dvb_vb2: drop wait_prepare/finish callbacks 2025-12-18 11:14:57 +01:00
dvbdev.c Convert more 'alloc_obj' cases to default GFP_KERNEL arguments 2026-02-21 20:03:00 -08:00
Kconfig media: Kconfig: cleanup VIDEO_DEV dependencies 2022-03-18 05:58:35 +01:00
Makefile lib/math: Move dvb_math.c into lib/math/int_log.c 2023-07-09 22:47:48 +01:00