From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH 02/11] ALSA: hda: Disable unsol event handling at error and shutdown paths
Date: Thu, 8 Oct 2026 21:25:42 +0200 [thread overview]
Message-ID: <20261008192553.300025-3-tiwai@suse.de> (raw)
In-Reply-To: <20261008192553.300025-1-tiwai@suse.de>
When the HD-audio controller driver probe fails, it still leaves the
unsolicited event handling and jackpoll work active, hence if they are
pending, they might fire up later after the resource gets released,
which may lead to a UAF. A similar problem may be seen at shutdown,
too.
Add the recently added helper to disable unsol events and the cancel
of jackpoll_work at the appropriate places.
Fixes: c3ec8ac82105 ("ASoC: hdac_hda: fix memleak on module unload")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
sound/hda/common/bind.c | 2 ++
sound/hda/common/codec.c | 1 +
2 files changed, 3 insertions(+)
diff --git a/sound/hda/common/bind.c b/sound/hda/common/bind.c
index 4772ca154a29..f2a498c78891 100644
--- a/sound/hda/common/bind.c
+++ b/sound/hda/common/bind.c
@@ -147,6 +147,8 @@ static int hda_codec_driver_probe(struct device *dev)
module_put(owner);
error:
+ snd_hdac_device_disable_unsol(&codec->core);
+ cancel_delayed_work_sync(&codec->jackpoll_work);
snd_hda_codec_cleanup_for_unbind(codec);
codec->preset = NULL;
return err;
diff --git a/sound/hda/common/codec.c b/sound/hda/common/codec.c
index c99fe61c29db..94da4f3a21ed 100644
--- a/sound/hda/common/codec.c
+++ b/sound/hda/common/codec.c
@@ -3039,6 +3039,7 @@ void snd_hda_codec_shutdown(struct hda_codec *codec)
codec->jackpoll_interval = 0; /* don't poll any longer */
cancel_delayed_work_sync(&codec->jackpoll_work);
+ snd_hdac_device_disable_unsol(&codec->core);
list_for_each_entry(cpcm, &codec->pcm_list_head, list)
snd_pcm_suspend_all(cpcm->pcm);
--
2.55.0
next prev parent reply other threads:[~2026-10-08 19:26 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
2026-10-08 19:25 ` [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too Takashi Iwai
2026-10-08 19:25 ` Takashi Iwai [this message]
2026-10-08 19:25 ` [PATCH 03/11] ALSA: hda: Add lock around codec->registered flag manipulations Takashi Iwai
2026-10-09 10:13 ` kernel test robot
2026-10-09 10:56 ` kernel test robot
2026-10-08 19:25 ` [PATCH 04/11] ALSA: hda: Add NULL check for the driver pointer at unsol event work Takashi Iwai
2026-10-08 19:25 ` [PATCH 05/11] ALSA: caiaq: Register card at the final step Takashi Iwai
2026-10-08 19:25 ` [PATCH 06/11] ALSA: caiaq: Fix races at MIDI URB and trigger accesses Takashi Iwai
2026-10-08 19:25 ` [PATCH 07/11] ALSA: usb: us16x08: Fix racy accesses of mixer elements Takashi Iwai
2026-10-08 19:25 ` [PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments Takashi Iwai
2026-10-08 19:25 ` [PATCH 09/11] ALSA: line6: Reject too small max packet sizes Takashi Iwai
2026-10-08 19:25 ` [PATCH 10/11] ALSA: line6: Fix potential OOB write in line6_capture_copy() Takashi Iwai
2026-10-08 19:25 ` [PATCH 11/11] ALSA: line6: Fix handling of zero-length capture packets Takashi Iwai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008192553.300025-3-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox