Skip to content

Commit 147996e

Browse files
sammiee5311tiwai
authored andcommitted
ALSA: usx2y: us144mkii: fix work UAF on disconnect
tascam_disconnect() cancels capture_work and midi_in_work before usb_kill_anchored_urbs() kills the capture/MIDI-in URBs. Those URBs self-resubmit, and their completion handlers reschedule the work. A URB that completes in the small window between cancel_work_sync() and usb_kill_anchored_urbs() therefore re-arms the work after its only cancel. Nothing cancels it again before snd_card_free() frees the card-private tascam structure, so the work handler then runs on freed memory. Kill the anchored URBs before cancelling the work; once the work is cancelled no remaining URB can complete to re-arm it. Fixes: c1bb0c1 ("ALSA: usb-audio: us144mkii: Implement audio capture and decoding") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4-8 Signed-off-by: HyeongJun An <sammiee5311@gmail.com> Link: https://patch.msgid.link/20260701095231.1020811-1-sammiee5311@gmail.com Signed-off-by: Takashi Iwai <tiwai@suse.de>
1 parent 6c18817 commit 147996e

1 file changed

Lines changed: 11 additions & 6 deletions

File tree

sound/usb/usx2y/us144mkii.c

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -585,19 +585,24 @@ static void tascam_disconnect(struct usb_interface *intf)
585585
return;
586586

587587
if (intf->cur_altsetting->desc.bInterfaceNumber == 0) {
588-
/* Ensure all deferred work is complete before freeing resources */
589588
snd_card_disconnect(tascam->card);
590-
cancel_work_sync(&tascam->stop_work);
591-
cancel_work_sync(&tascam->capture_work);
592-
cancel_work_sync(&tascam->midi_in_work);
593-
cancel_work_sync(&tascam->midi_out_work);
594-
cancel_work_sync(&tascam->stop_pcm_work);
595589

590+
/*
591+
* Kill the URBs before cancelling the work, so a late URB
592+
* completion cannot re-arm a work that then runs after
593+
* snd_card_free().
594+
*/
596595
usb_kill_anchored_urbs(&tascam->playback_anchor);
597596
usb_kill_anchored_urbs(&tascam->capture_anchor);
598597
usb_kill_anchored_urbs(&tascam->feedback_anchor);
599598
usb_kill_anchored_urbs(&tascam->midi_in_anchor);
600599
usb_kill_anchored_urbs(&tascam->midi_out_anchor);
600+
601+
cancel_work_sync(&tascam->stop_work);
602+
cancel_work_sync(&tascam->capture_work);
603+
cancel_work_sync(&tascam->midi_in_work);
604+
cancel_work_sync(&tascam->midi_out_work);
605+
cancel_work_sync(&tascam->stop_pcm_work);
601606
timer_delete_sync(&tascam->error_timer);
602607
tascam_free_urbs(tascam);
603608
snd_card_free(tascam->card);

0 commit comments

Comments
 (0)