media: cedrus: fix double free
authorDaniel Almeida <daniel.almeida@collabora.com>
Fri, 2 Jul 2021 02:01:28 +0000 (03:01 +0100)
committerMauro Carvalho Chehab <mchehab+huawei@kernel.org>
Mon, 18 Oct 2021 15:29:34 +0000 (16:29 +0100)
If v4l2_ctrl_new_custom fails in cedrus_init_ctrls the error path will
free ctx->ctrls, which is also freed in cedrus release. Fix this by
setting ctx->ctrls to NULL instead of inadvertently removing kfree
calls.

Signed-off-by: Daniel Almeida <daniel.almeida@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
drivers/staging/media/sunxi/cedrus/cedrus.c

index 9dd30cb..c76fc97 100644 (file)
@@ -259,6 +259,7 @@ static int cedrus_init_ctrls(struct cedrus_dev *dev, struct cedrus_ctx *ctx)
 
                        v4l2_ctrl_handler_free(hdl);
                        kfree(ctx->ctrls);
+                       ctx->ctrls = NULL;
                        return hdl->error;
                }