From: Takashi Iwai <tiwai@suse.de>
To: "syzbot" <syzbot@kernel.org>
Cc: syzkaller-bugs@googlegroups.com,
Aleksandr Nogikh <nogikh@google.com>,
<linux-sound@vger.kernel.org>, "Jaroslav Kysela" <perex@perex.cz>,
"Takashi Iwai" <tiwai@suse.com>, "Takashi Iwai" <tiwai@suse.de>,
broonie@kernel.org, cassiogabrielcontato@gmail.com,
cezary.rojewski@intel.com, kees@kernel.org,
linux-kernel@vger.kernel.org, syzbot@lists.linux.dev
Subject: Re: [PATCH] ALSA: core: Fix use-after-free in snd_card_do_free()
Date: Fri, 14 Aug 2026 14:14:12 +0200 [thread overview]
Message-ID: <877blsew6j.wl-tiwai@suse.de> (raw)
In-Reply-To: <02042186-27b7-42a9-b64e-f93ce8fbe05a@mail.kernel.org>
On Fri, 14 Aug 2026 14:05:43 +0200,
syzbot wrote:
>
> From: Aleksandr Nogikh <nogikh@google.com>
>
> A use-after-free was detected in snd_card_do_free() when a sound card
> managed by devres is unbound while a user-space application still holds an
> open file descriptor.
>
> For managed cards, the memory is allocated using devres_alloc(), and its
> release function is set to __snd_card_release(), which calls
> snd_card_free(). When the device is unbound, the unbind thread calls
> snd_card_free(), which drops a reference to the card's device. If the user
> thread still has an open file descriptor, the reference count does not
> reach zero, and the unbind thread blocks on wait_for_completion(&released).
>
> When the user thread closes the file descriptor, it drops the final
> reference, invoking the device release callback release_card_device(),
> which calls snd_card_do_free(). snd_card_do_free() performs cleanup and
> calls complete(card->release_completion). This wakes up the unbind thread,
> which returns from snd_card_free() and __snd_card_release(). The devres
> core then immediately frees the memory block containing the snd_card
> structure.
>
> Meanwhile, the user thread continues execution in snd_card_do_free() and
> evaluates `if (!card->managed)`. It reads the `managed` boolean from the
> snd_card structure that was just freed by the unbind thread, triggering a
> KASAN use-after-free.
>
> Fix this by caching the value of card->managed in a local variable before
> calling complete(). This ensures that the card pointer is not dereferenced
> after the unbind thread has been woken up and potentially freed the card.
>
> BUG: KASAN: use-after-free in snd_card_do_free sound/core/init.c:604
> [inline]
> BUG: KASAN: use-after-free in release_card_device+0x1ab/0x1b0
> sound/core/init.c:153
> Read of size 1 at addr ffff8881912ec909 by task syz-executor130/5857
>
> Call Trace:
> <TASK>
> dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
> print_address_description+0x55/0x1e0 mm/kasan/report.c:378
> print_report+0x58/0x70 mm/kasan/report.c:482
> kasan_report+0x117/0x150 mm/kasan/report.c:595
> snd_card_do_free sound/core/init.c:604 [inline]
> release_card_device+0x1ab/0x1b0 sound/core/init.c:153
> device_release+0xc4/0x1f0 drivers/base/core.c:-1
> kobject_cleanup lib/kobject.c:689 [inline]
> kobject_release lib/kobject.c:720 [inline]
> kref_put include/linux/kref.h:65 [inline]
> kobject_put+0x222/0x550 lib/kobject.c:737
> snd_card_file_remove+0x331/0x390 sound/core/init.c:1125
> snd_pcm_release+0x12c/0x160 sound/core/pcm_native.c:2986
> __fput+0x418/0xa50 fs/file_table.c:512
> fput_close_sync+0x11f/0x240 fs/file_table.c:617
> __do_sys_close fs/open.c:1511 [inline]
> __se_sys_close fs/open.c:1496 [inline]
> __x64_sys_close+0x7e/0x110 fs/open.c:1496
> do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
> do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
> </TASK>
>
> Fixes: e8ad415b7a55 ("ALSA: core: Add managed card creation")
> Assisted-by: Gemini:gemini-3.6-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: syzbot+7061d72c26b7daebe2b4@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=7061d72c26b7daebe2b4
> Link: https://syzkaller.appspot.com/ai_job?id=24752a23-f0b6-49c1-bf20-4fa89c2e7eb2
> Signed-off-by: Aleksandr Nogikh <nogikh@google.com>
Applied to for-next branch. Thanks.
Takashi
prev parent reply other threads:[~2026-08-14 12:14 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 12:05 [PATCH] ALSA: core: Fix use-after-free in snd_card_do_free() syzbot
2026-08-14 12:14 ` Takashi Iwai [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=877blsew6j.wl-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=broonie@kernel.org \
--cc=cassiogabrielcontato@gmail.com \
--cc=cezary.rojewski@intel.com \
--cc=kees@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
--cc=nogikh@google.com \
--cc=perex@perex.cz \
--cc=syzbot@kernel.org \
--cc=syzbot@lists.linux.dev \
--cc=syzkaller-bugs@googlegroups.com \
--cc=tiwai@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.