aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTakashi Iwai <tiwai@suse.de>2026-07-26 09:48:19 +0200
committerTakashi Iwai <tiwai@suse.de>2026-07-26 10:02:01 +0200
commita54bf16965f896415c3337bc4fbb40fb11941d99 (patch)
tree0b17a292c7cd4637fbd60d0a72a745ba96a891c3
parent0970274613fb463d376211450cab066d34ebfe6a (diff)
ALSA: 6fire: Fix UAF at error handling during probe
Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF. This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path. Reported-and-tested-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com> Closes: https://lore.kernel.org/20260724030900.1984491-1-shuangpeng.kernel@gmail.com Cc: <stable@vger.kernel.org> Link: https://patch.msgid.link/20260726074821.2288158-1-tiwai@suse.de Signed-off-by: Takashi Iwai <tiwai@suse.de>
-rw-r--r--sound/usb/6fire/chip.c4
1 files changed, 4 insertions, 0 deletions
diff --git a/sound/usb/6fire/chip.c b/sound/usb/6fire/chip.c
index 2c5648966412..6cf410a92fa2 100644
--- a/sound/usb/6fire/chip.c
+++ b/sound/usb/6fire/chip.c
@@ -150,6 +150,10 @@ static int usb6fire_chip_probe(struct usb_interface *intf,
return 0;
destroy_chip:
+ chip->shutdown = true;
+ if (card)
+ snd_card_disconnect(card);
+ usb6fire_chip_abort(chip);
snd_card_free(card);
return ret;
}