]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
ASoC: SOF: ipc3-topology: Set scontrol->priv to NULL after freeing it
authorPeter Ujfalusi <peter.ujfalusi@linux.intel.com>
Thu, 31 Mar 2022 11:47:57 +0000 (14:47 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 9 Jun 2022 08:29:55 +0000 (10:29 +0200)
[ Upstream commit a403993ce98fb401f696da7c4f374739a7609cff ]

Since the scontrol->priv is freed up during load operation it should be set
to NULL to be safe against double freeing attempt.

Fixes: b5cee8feb1d48 ("ASoC: SOF: topology: Make control parsing IPC agnostic")
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Reviewed-by: Ranjani Sridharan <ranjani.sridharan@linux.intel.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.intel.com>
Link: https://lore.kernel.org/r/20220331114757.32551-1-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
sound/soc/sof/ipc3-topology.c

index af1bbd34213c119f9b3e3791a4bf214799cc56fe..cdff48c4195f89f1c813301391ee16275b6e3a67 100644 (file)
@@ -1605,6 +1605,7 @@ static int sof_ipc3_control_load_bytes(struct snd_sof_dev *sdev, struct snd_sof_
        if (scontrol->priv_size > 0) {
                memcpy(cdata->data, scontrol->priv, scontrol->priv_size);
                kfree(scontrol->priv);
+               scontrol->priv = NULL;
 
                if (cdata->data->magic != SOF_ABI_MAGIC) {
                        dev_err(sdev->dev, "Wrong ABI magic 0x%08x.\n", cdata->data->magic);