Re: [PATCH] ALSA: ump: fix double free of out_cvts on rawmidi error
Takashi Iwai <[email protected]>
| Newsgroups | org.kernel.vger.linux-sound,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 26 Jul 2026 07:16:33 +0200, Baul Lee wrote: > > snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array > ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with > kfree() but leaves ump->out_cvts pointing at the freed memory. When the > endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts > a second time, resulting in a double free. > > The host snd-usb-audio driver attaches the legacy rawmidi for any USB > MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail > reaches this path on enumeration. > > Clear ump->out_cvts after freeing it on the error path so it is not > freed again during teardown. > > Discovered by XBOW, triaged by Baul Lee <[email protected]> > > Fixes: 33cd7630782d ("ALSA: ump: Export MIDI1 / UMP conversion helpers") > Reported-by: Federico Kirschbaum <[email protected]> > Reported-by: Baul Lee <[email protected]> > Cc: [email protected] > Signed-off-by: Baul Lee <[email protected]> Applied now. Thanks. Takashi