[PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure
Deepanshu Kartikey <[email protected]>
| Newsgroups | org.kernel.vger.linux-sound,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
If snd_rawmidi_new() fails inside snd_ump_attach_legacy_rawmidi(), the error path frees ump->out_cvts but leaves the pointer dangling. Since ump->out_cvts is a field of the long-lived struct snd_ump_endpoint (not the rawmidi device that failed to be created), it gets freed a second time later during normal endpoint teardown, in snd_ump_endpoint_free(), invoked via snd_rawmidi_free()'s private_free callback when the sound card is released. This results in a KASAN double-free/invalid-free. Clear ump->out_cvts to NULL after freeing it on the error path, so the later unconditional kfree() in snd_ump_endpoint_free() becomes a harmless no-op. Reported-by: [email protected] Closes: https://syzkaller.appspot.com/bug?extid=b6cab840e6a85641c7ad Signed-off-by: Deepanshu Kartikey <[email protected]> --- sound/core/ump.c | 1 + 1 file changed, 1 insertion(+) diff --git a/sound/core/ump.c b/sound/core/ump.c index 70520c7ca293..632c13baf21e 100644 --- a/sound/core/ump.c +++ b/sound/core/ump.c @@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump, &rmidi); if (err < 0) { kfree(ump->out_cvts); + ump->out_cvts = NULL; return err; } -- 2.43.0