Re: [PATCH] ALSA: core: Fix use-after-free in snd_card_do_free()
Takashi Iwai <[email protected]>
| Newsgroups | org.kernel.vger.linux-sound,dev.linux.lists.syzbot,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 14 Aug 2026 14:05:43 +0200, syzbot wrote: > > From: Aleksandr Nogikh <[email protected]> > > A use-after-free was detected in snd_card_do_free() when a sound card > managed by devres is unbound while a user-space application still holds an > open file descriptor. > > For managed cards, the memory is allocated using devres_alloc(), and its > release function is set to __snd_card_release(), which calls > snd_card_free(). When the device is unbound, the unbind thread calls > snd_card_free(), which drops a reference to the card's device. If the user > thread still has an open file descriptor, the reference count does not > reach zero, and the unbind thread blocks on wait_for_completion(&released). > > When the user thread closes the file descriptor, it drops the final > reference, invoking the device release callback release_card_device(), > which calls snd_card_do_free(). snd_card_do_free() performs cleanup and > calls complete(card->release_completion). This wakes up the unbind thread, > which returns from snd_card_free() and __snd_card_release(). The devres > core then immediately frees the memory block containing the snd_card > structure. > > Meanwhile, the user thread continues execution in snd_card_do_free() and > evaluates `if (!card->managed)`. It reads the `managed` boolean from the > snd_card structure that was just freed by the unbind thread, triggering a > KASAN use-after-free. > > Fix this by caching the value of card->managed in a local variable before > calling complete(). This ensures that the card pointer is not dereferenced > after the unbind thread has been woken up and potentially freed the card. > > BUG: KASAN: use-after-free in snd_card_do_free sound/core/init.c:604 > [inline] > BUG: KASAN: use-after-free in release_card_device+0x1ab/0x1b0 > sound/core/init.c:153 > Read of size 1 at addr ffff8881912ec909 by task syz-executor130/5857 > > Call Trace: > <TASK> > dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 > print_address_description+0x55/0x1e0 mm/kasan/report.c:378 > print_report+0x58/0x70 mm/kasan/report.c:482 > kasan_report+0x117/0x150 mm/kasan/report.c:595 > snd_card_do_free sound/core/init.c:604 [inline] > release_card_device+0x1ab/0x1b0 sound/core/init.c:153 > device_release+0xc4/0x1f0 drivers/base/core.c:-1 > kobject_cleanup lib/kobject.c:689 [inline] > kobject_release lib/kobject.c:720 [inline] > kref_put include/linux/kref.h:65 [inline] > kobject_put+0x222/0x550 lib/kobject.c:737 > snd_card_file_remove+0x331/0x390 sound/core/init.c:1125 > snd_pcm_release+0x12c/0x160 sound/core/pcm_native.c:2986 > __fput+0x418/0xa50 fs/file_table.c:512 > fput_close_sync+0x11f/0x240 fs/file_table.c:617 > __do_sys_close fs/open.c:1511 [inline] > __se_sys_close fs/open.c:1496 [inline] > __x64_sys_close+0x7e/0x110 fs/open.c:1496 > do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] > do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 > entry_SYSCALL_64_after_hwframe+0x77/0x7f > </TASK> > > Fixes: e8ad415b7a55 ("ALSA: core: Add managed card creation") > Assisted-by: Gemini:gemini-3.6-flash Gemini:gemini-3.1-pro-preview syzbot > Reported-by: [email protected] > Closes: https://syzkaller.appspot.com/bug?extid=7061d72c26b7daebe2b4 > Link: https://syzkaller.appspot.com/ai_job?id=24752a23-f0b6-49c1-bf20-4fa89c2e7eb2 > Signed-off-by: Aleksandr Nogikh <[email protected]> Applied to for-next branch. Thanks. Takashi