From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6455A53C3C0; Wed, 23 Sep 2026 14:45:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174708; cv=none; b=fvfiZuhhWqn8l6dPu9lRZ/koHyneBTKfyiwU/3523Zd3lmz/Yi1noU404jpZe+5vcHuCvUzM6WKugfNKsXZ0aSQkAUOuonhDkuQVxmEuY+JAvUc+nicFHxZc/sPlimnrUsWus1/CfYL0Oc35cs1Xi+781UGkoEhtTIwSHDzAeQU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174708; c=relaxed/simple; bh=WY53UuiR9+yhFz8rm0QMLgF9YyCbLwIiQfjPSBnEKgY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FmXvKj/d/FjDgvrueR9/5Ku2J5Ng1v8Wz7+HZ2TS8WMZAN6bhOnLNSJ5Kx/lfiF7JQwP2oeHJA/cGYSEFcjVd05a5bBOM7tGp3BfFXxmGByjd+Asy3lm72LUwTvQQB5snHI1fYVj61t84PROfpBXOZnQpuVo2GpPJZrCMA45ATQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=D+NJD6lt; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="D+NJD6lt" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B6A101F000FF; Wed, 23 Sep 2026 14:45:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790174707; bh=Ws0QcKxbxkbgy94KUxm4cUwce91rNEZWuu1Ywu94X9E=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=D+NJD6ltKpqQbLZHvk9nf6Bf4x8xcPXst5TBER3dFo8B+ZWpPVE2xYWsD5gbBxVmv x+v/uqkFmtZni1/K1Yv5GrmiQRi3RUKI5PWtle4Jwdk9tdz7nKWPQerwTxO2tYwfBL sBkMKio2LmN0FR55NJ76vYpEpAfjOYzdPDntltqI= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Farhad Alemi , Takashi Iwai Subject: [PATCH 6.18 199/398] ALSA: core: Fix potential UAF after asynchronous card release Date: Wed, 23 Sep 2026 16:04:33 +0200 Message-ID: <20260923140648.583015182@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Takashi Iwai commit fd95e68df6fe66344161a1329cbe5e5805e7b704 upstream. Usually a sound driver releases the resources assigned to the card via snd_card_free(), and it synchronizes with the whole release procedure. However, when the card is released asynchronously via snd_card_free_when_closed() like USB-audio driver, the situation is slightly different; although the snd_card_disconnect() call at the disconnection guarantees that any newer accesses will be gated, the in-flight tasks might be still accessing to the underlying card->dev device even after the disconnection, which would cause a use-after-free in the end, as reported by fuzzers. For addressing the bug above, this patch takes the refcount of card->dev at initialization of the card object, and releases at its destructor. This assures the availability of the card->dev in its whole lifecycle. Reported-by: Farhad Alemi Closes: https://lore.kernel.org/CA+0ovChexj4TrZL_2iG_P0WBEbZc5+73GfB3DkciQi=R8pZOnA@mail.gmail.com Closes: https://lore.kernel.org/CA+0ovCgQUQNN=Z1tJTouiCsDaXR5M-3-SQEGk-cpPXQkM5Xh+w@mail.gmail.com Cc: Link: https://patch.msgid.link/20260912162150.455144-1-tiwai@suse.de Signed-off-by: Takashi Iwai Signed-off-by: Greg Kroah-Hartman --- sound/core/init.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) --- a/sound/core/init.c +++ b/sound/core/init.c @@ -309,7 +309,7 @@ static int snd_card_init(struct snd_card kfree(card); /* manually free here, as no destructor called */ return err; } - card->dev = parent; + card->dev = get_device(parent); card->number = idx; WARN_ON(IS_MODULE(CONFIG_SND) && !module); card->module = module; @@ -593,6 +593,7 @@ static int snd_card_do_free(struct snd_c dev_warn(card->dev, "unable to free card info\n"); /* Not fatal error */ } + put_device(card->dev); if (card->release_completion) complete(card->release_completion); if (!managed)