]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
ALSA: ump: fix double free of out_cvts on rawmidi error
authorBaul Lee <baul.lee@xbow.com>
Sun, 26 Jul 2026 05:16:33 +0000 (14:16 +0900)
committerTakashi Iwai <tiwai@suse.de>
Sun, 26 Jul 2026 06:59:26 +0000 (08:59 +0200)
snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array
ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with
kfree() but leaves ump->out_cvts pointing at the freed memory.  When the
endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts
a second time, resulting in a double free.

The host snd-usb-audio driver attaches the legacy rawmidi for any USB
MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail
reaches this path on enumeration.

Clear ump->out_cvts after freeing it on the error path so it is not
freed again during teardown.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

Fixes: 33cd7630782d ("ALSA: ump: Export MIDI1 / UMP conversion helpers")
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260726051633.41206-1-baul.lee@xbow.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
sound/core/ump.c

index 70520c7ca293aba08fc9fcd9ccca651576a866ba..632c13baf21e10e35b3369ae2d7f7171fa68b476 100644 (file)
@@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump,
                              &rmidi);
        if (err < 0) {
                kfree(ump->out_cvts);
+               ump->out_cvts = NULL;
                return err;
        }