All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: [PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure
       [not found] <20260729001509.11164-1-kartikey406@gmail.com>
@ 2026-07-29  0:15 ` syzbot
  0 siblings, 0 replies; 5+ messages in thread
From: syzbot @ 2026-07-29  0:15 UTC (permalink / raw)
  To: kartikey406; +Cc: kartikey406, linux-kernel, syzkaller-bugs

> #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master

This crash does not have a reproducer. I cannot test it.

>
>
> If snd_rawmidi_new() fails inside snd_ump_attach_legacy_rawmidi(), the
> error path frees ump->out_cvts but leaves the pointer dangling. Since
> ump->out_cvts is a field of the long-lived struct snd_ump_endpoint
> (not the rawmidi device that failed to be created), it gets freed a
> second time later during normal endpoint teardown, in
> snd_ump_endpoint_free(), invoked via snd_rawmidi_free()'s
> private_free callback when the sound card is released. This results
> in a KASAN double-free/invalid-free.
>
> Clear ump->out_cvts to NULL after freeing it on the error path, so
> the later unconditional kfree() in snd_ump_endpoint_free() becomes a
> harmless no-op.
>
> Reported-by: syzbot+b6cab840e6a85641c7ad@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=b6cab840e6a85641c7ad
> Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
> ---
>  sound/core/ump.c | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/sound/core/ump.c b/sound/core/ump.c
> index 70520c7ca293..632c13baf21e 100644
> --- a/sound/core/ump.c
> +++ b/sound/core/ump.c
> @@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump,
>  			      &rmidi);
>  	if (err < 0) {
>  		kfree(ump->out_cvts);
> +		ump->out_cvts = NULL;
>  		return err;
>  	}
>  
> -- 
> 2.43.0
>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure
       [not found] <20260729001642.11188-1-kartikey406@gmail.com>
@ 2026-07-29  0:16 ` syzbot
  0 siblings, 0 replies; 5+ messages in thread
From: syzbot @ 2026-07-29  0:16 UTC (permalink / raw)
  To: kartikey406; +Cc: kartikey406, linux-kernel, syzkaller-bugs

> #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master

This crash does not have a reproducer. I cannot test it.

>
>
> If snd_rawmidi_new() fails inside snd_ump_attach_legacy_rawmidi(), the
> error path frees ump->out_cvts but leaves the pointer dangling. Since
> ump->out_cvts is a field of the long-lived struct snd_ump_endpoint
> (not the rawmidi device that failed to be created), it gets freed a
> second time later during normal endpoint teardown, in
> snd_ump_endpoint_free(), invoked via snd_rawmidi_free()'s
> private_free callback when the sound card is released. This results
> in a KASAN double-free/invalid-free.
>
> Clear ump->out_cvts to NULL after freeing it on the error path, so
> the later unconditional kfree() in snd_ump_endpoint_free() becomes a
> harmless no-op.
>
> Reported-by: syzbot+b6cab840e6a85641c7ad@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=b6cab840e6a85641c7ad
> Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
> ---
>  sound/core/ump.c | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/sound/core/ump.c b/sound/core/ump.c
> index 70520c7ca293..632c13baf21e 100644
> --- a/sound/core/ump.c
> +++ b/sound/core/ump.c
> @@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump,
>  			      &rmidi);
>  	if (err < 0) {
>  		kfree(ump->out_cvts);
> +		ump->out_cvts = NULL;
>  		return err;
>  	}
>  
> -- 
> 2.43.0
>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure
       [not found] <20260729001845.11372-1-kartikey406@gmail.com>
@ 2026-07-29  0:18 ` syzbot
  0 siblings, 0 replies; 5+ messages in thread
From: syzbot @ 2026-07-29  0:18 UTC (permalink / raw)
  To: kartikey406; +Cc: kartikey406, linux-kernel, syzkaller-bugs

> #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master

This crash does not have a reproducer. I cannot test it.

>
> If snd_rawmidi_new() fails inside snd_ump_attach_legacy_rawmidi(), the
> error path frees ump->out_cvts but leaves the pointer dangling. Since
> ump->out_cvts is a field of the long-lived struct snd_ump_endpoint
> (not the rawmidi device that failed to be created), it gets freed a
> second time later during normal endpoint teardown, in
> snd_ump_endpoint_free(), invoked via snd_rawmidi_free()'s
> private_free callback when the sound card is released. This results
> in a KASAN double-free/invalid-free.
>
> Clear ump->out_cvts to NULL after freeing it on the error path, so
> the later unconditional kfree() in snd_ump_endpoint_free() becomes a
> harmless no-op.
>
> Reported-by: syzbot+b6cab840e6a85641c7ad@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=b6cab840e6a85641c7ad
> Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
> ---
>  sound/core/ump.c | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/sound/core/ump.c b/sound/core/ump.c
> index 70520c7ca293..632c13baf21e 100644
> --- a/sound/core/ump.c
> +++ b/sound/core/ump.c
> @@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump,
>  			      &rmidi);
>  	if (err < 0) {
>  		kfree(ump->out_cvts);
> +		ump->out_cvts = NULL;
>  		return err;
>  	}
>  
> -- 
> 2.43.0
>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure
       [not found] <20260729002134.11433-1-kartikey406@gmail.com>
@ 2026-07-29  0:21 ` syzbot
  0 siblings, 0 replies; 5+ messages in thread
From: syzbot @ 2026-07-29  0:21 UTC (permalink / raw)
  To: kartikey406; +Cc: kartikey406, linux-kernel, syzkaller-bugs

> #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci

This crash does not have a reproducer. I cannot test it.

>
> If snd_rawmidi_new() fails inside snd_ump_attach_legacy_rawmidi(), the
> error path frees ump->out_cvts but leaves the pointer dangling. Since
> ump->out_cvts is a field of the long-lived struct snd_ump_endpoint
> (not the rawmidi device that failed to be created), it gets freed a
> second time later during normal endpoint teardown, in
> snd_ump_endpoint_free(), invoked via snd_rawmidi_free()'s
> private_free callback when the sound card is released. This results
> in a KASAN double-free/invalid-free.
>
> Clear ump->out_cvts to NULL after freeing it on the error path, so
> the later unconditional kfree() in snd_ump_endpoint_free() becomes a
> harmless no-op.
>
> Reported-by: syzbot+b6cab840e6a85641c7ad@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=b6cab840e6a85641c7ad
> Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
> ---
>  sound/core/ump.c | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/sound/core/ump.c b/sound/core/ump.c
> index 70520c7ca293..632c13baf21e 100644
> --- a/sound/core/ump.c
> +++ b/sound/core/ump.c
> @@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump,
>  			      &rmidi);
>  	if (err < 0) {
>  		kfree(ump->out_cvts);
> +		ump->out_cvts = NULL;
>  		return err;
>  	}
>  
> -- 
> 2.43.0
>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure
@ 2026-07-29  0:23 Deepanshu Kartikey
  0 siblings, 0 replies; 5+ messages in thread
From: Deepanshu Kartikey @ 2026-07-29  0:23 UTC (permalink / raw)
  To: perex, tiwai
  Cc: kees, linux-sound, linux-kernel, Deepanshu Kartikey,
	syzbot+b6cab840e6a85641c7ad

If snd_rawmidi_new() fails inside snd_ump_attach_legacy_rawmidi(), the
error path frees ump->out_cvts but leaves the pointer dangling. Since
ump->out_cvts is a field of the long-lived struct snd_ump_endpoint
(not the rawmidi device that failed to be created), it gets freed a
second time later during normal endpoint teardown, in
snd_ump_endpoint_free(), invoked via snd_rawmidi_free()'s
private_free callback when the sound card is released. This results
in a KASAN double-free/invalid-free.

Clear ump->out_cvts to NULL after freeing it on the error path, so
the later unconditional kfree() in snd_ump_endpoint_free() becomes a
harmless no-op.

Reported-by: syzbot+b6cab840e6a85641c7ad@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b6cab840e6a85641c7ad
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
---
 sound/core/ump.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/core/ump.c b/sound/core/ump.c
index 70520c7ca293..632c13baf21e 100644
--- a/sound/core/ump.c
+++ b/sound/core/ump.c
@@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump,
 			      &rmidi);
 	if (err < 0) {
 		kfree(ump->out_cvts);
+		ump->out_cvts = NULL;
 		return err;
 	}
 
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-07-29  0:23 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <20260729001642.11188-1-kartikey406@gmail.com>
2026-07-29  0:16 ` [PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure syzbot
2026-07-29  0:23 Deepanshu Kartikey
     [not found] <20260729002134.11433-1-kartikey406@gmail.com>
2026-07-29  0:21 ` syzbot
     [not found] <20260729001845.11372-1-kartikey406@gmail.com>
2026-07-29  0:18 ` syzbot
     [not found] <20260729001509.11164-1-kartikey406@gmail.com>
2026-07-29  0:15 ` syzbot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.