mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
In capture_urb_complete(), usb_anchor_urb() is called on every
completion callback, but the URB is already anchored from the
initial submission in tascam_trigger_start(). Each redundant call
corrupts the anchor's doubly-linked list and inflates the URB
refcount. When usb_kill_anchored_urbs() traverses the list during
stream stop / suspend / disconnect, the corrupted list leads to
use-after-free.
Remove the redundant usb_anchor_urb() from the resubmit path.
Cc: stable@vger.kernel.org
Fixes: c1bb0c13e4 ("ALSA: usb-audio: us144mkii: Implement audio capture and decoding")
Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260627042949.61767-1-vulab@iscas.ac.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
This commit is contained in:
parent
dc59e4fea9
commit
5cff1529a2
|
|
@ -302,7 +302,6 @@ void capture_urb_complete(struct urb *urb)
|
|||
}
|
||||
|
||||
usb_get_urb(urb);
|
||||
usb_anchor_urb(urb, &tascam->capture_anchor);
|
||||
ret = usb_submit_urb(urb, GFP_ATOMIC);
|
||||
if (ret < 0) {
|
||||
dev_err_ratelimited(tascam->card->dev,
|
||||
|
|
@ -312,6 +311,7 @@ void capture_urb_complete(struct urb *urb)
|
|||
usb_put_urb(urb);
|
||||
atomic_dec(
|
||||
&tascam->active_urbs); /* Decrement on failed resubmission */
|
||||
return;
|
||||
}
|
||||
out:
|
||||
usb_put_urb(urb);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user