Re: [PATCH] ALSA: us144mkii: re-anchor capture URBs on resubmission
Takashi Iwai <[email protected]> Tue, 04 Aug 2026 18:07:09 +0200
| Newsgroups | org.kernel.vger.linux-sound,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 04 Aug 2026 14:36:25 +0200, Baul Lee wrote: > > capture_urb_complete() resubmits each capture URB without anchoring it: > > usb_get_urb(urb); > ret = usb_submit_urb(urb, GFP_ATOMIC); > > Anchoring is a property of a submission, not of the URB. The giveback > path calls usb_unanchor_urb() before urb->complete(), so an URB > resubmitted from its own completion handler is off the anchor. The > capture URBs are anchored once, at stream start, so from the first > completion onward tascam->capture_anchor is empty. > > tascam_free_urbs(), tascam_disconnect(), tascam_suspend() and the > stop-work path all call usb_kill_anchored_urbs(&tascam->capture_anchor) > to reap the capture URBs before anything is freed. With the anchor empty > those calls return immediately and the URBs stay queued on the host > controller. > > tascam_free_urbs() then returns the capture transfer buffers with > usb_free_coherent(), and snd_card_free() releases the snd_card > allocation that embeds tascam (card->private_data). The controller > completes the queued URBs afterwards, writing device-supplied data into > the freed transfer buffer, and capture_urb_complete() dereferences the > freed driver object. > > KASAN on 7.2.0-rc5 (arm64): > > BUG: KASAN: slab-use-after-free in dummy_timer > Write of size 512 at addr ffff000015b62000 > __asan_memcpy > dummy_timer > hrtimer_run_softirq > Allocated by task 64: > usb_alloc_coherent > tascam_alloc_urbs > tascam_probe > Freed by task 170: > usb_free_coherent > tascam_free_urbs > tascam_disconnect > usb_unbind_interface > > BUG: KASAN: slab-use-after-free in capture_urb_complete > Read of size 4 at addr ffff0000170ee878 > Freed by task 170: > release_card_device > snd_card_free > tascam_disconnect > > Restore the usb_anchor_urb() between the reference count bump and the > resubmission. That also makes the handler's usb_unanchor_urb() failure > arm meaningful again and restores usb_kill_anchored_urbs() as a barrier > on the disconnect, suspend and stop-work paths. > > The anchoring was removed on the premise that the URB is already anchored > from the initial submission, which does not hold once the first giveback > has run. > > Discovered by XBOW, triaged by Baul Lee <[email protected]> > > Fixes: 5cff1529a2f9 ("ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission") > Reported-by: Federico Kirschbaum <[email protected]> > Reported-by: Baul Lee <[email protected]> > Cc: [email protected] > Signed-off-by: Baul Lee <[email protected]> Applied now. Thanks. Takashi