diff options
| author | Takashi Iwai <tiwai@suse.de> | 2026-07-26 09:48:19 +0200 |
|---|---|---|
| committer | Takashi Iwai <tiwai@suse.de> | 2026-07-26 10:02:01 +0200 |
| commit | a54bf16965f896415c3337bc4fbb40fb11941d99 (patch) | |
| tree | 0b17a292c7cd4637fbd60d0a72a745ba96a891c3 | |
| parent | 0970274613fb463d376211450cab066d34ebfe6a (diff) | |
ALSA: 6fire: Fix UAF at error handling during probe
Although 6fire driver had a few fixes for dealing with the early error
handling during the probe phase, it forgot a pending URB before
freeing the resources, which may lead to a UAF.
This patch addresses it by doing the almost same cleanup procedure
like the normal disconnect phase at the error path.
Reported-and-tested-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Closes: https://lore.kernel.org/20260724030900.1984491-1-shuangpeng.kernel@gmail.com
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260726074821.2288158-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
| -rw-r--r-- | sound/usb/6fire/chip.c | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/sound/usb/6fire/chip.c b/sound/usb/6fire/chip.c index 2c5648966412..6cf410a92fa2 100644 --- a/sound/usb/6fire/chip.c +++ b/sound/usb/6fire/chip.c @@ -150,6 +150,10 @@ static int usb6fire_chip_probe(struct usb_interface *intf, return 0; destroy_chip: + chip->shutdown = true; + if (card) + snd_card_disconnect(card); + usb6fire_chip_abort(chip); snd_card_free(card); return ret; } |
