Re: [PATCH] ALSA: hda: cs35l41: validate and free ACPI mute object

From: Takashi Iwai

Date: Wed Jul 15 2026 - 10:58:05 EST


On Wed, 08 Jul 2026 13:36:25 +0200,
Guangshuo Li wrote:
>
> cs35l41_get_acpi_mute_state() evaluates a _DSM method to get the ACPI
> mute state and reads the first byte from the returned object.
>
> However, the returned ACPI object is owned by the caller and is never
> freed after use, so each successful query leaks the _DSM result object.
>
> The code also assumes that the returned object is a buffer with at least
> one byte. A malformed firmware response can return a different object
> type or an empty buffer, and the direct ret->buffer.pointer dereference
> can then access an invalid pointer.
>
> Use the typed _DSM helper, validate that the returned buffer contains at
> least one byte, and free the ACPI object after reading it.
>
> Fixes: 447106e92a0c ("ALSA: hda: cs35l41: Support mute notifications for CS35L41 HDA")
> Signed-off-by: Guangshuo Li <lgs201920130244@xxxxxxxxx>

Applied now. Thanks.


Takashi