[PATCH 2/8] ALSA: pcm: Fix TOCTOU state overwrite in snd_pcm_drop()
From: Takashi Iwai
Date: Tue Oct 06 2026 - 09:43:47 EST
snd_pcm_drop() checks the current state at the beginning, and bails
out if it's in an invalid state (OPEN or DISCONNECTED). However,
since the check is done before the PCM stream lock, this can lead to a
Time-of-Check to Time-of-Use (TOCTOU) race against the other forcible
state change like the device disconnection like below:
CPU 0 CPU 1
----- -----
snd_pcm_drop()
runtime->state check
snd_pcm_dev_disconnect()
guard(pcm_stream_lock_irq)
runtime->state = SNDRV_PCM_STATE_DISCONNECTED
guard(pcm_stream_lock_irq)
snd_pcm_stop(SNDRV_PCM_STATE_SETUP) <== inconsistent state
For avoiding the inconsistent state change, this patch moves the
runtime state check inside the stream lock guard.
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Signed-off-by: Takashi Iwai <tiwai@xxxxxxx>
---
sound/core/pcm_native.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/core/pcm_native.c b/sound/core/pcm_native.c
index 6efaebc7f8b4..defbb2977efe 100644
--- a/sound/core/pcm_native.c
+++ b/sound/core/pcm_native.c
@@ -2289,11 +2289,11 @@ static int snd_pcm_drop(struct snd_pcm_substream *substream)
return -ENXIO;
runtime = substream->runtime;
+ guard(pcm_stream_lock_irq)(substream);
if (runtime->state == SNDRV_PCM_STATE_OPEN ||
runtime->state == SNDRV_PCM_STATE_DISCONNECTED)
return -EBADFD;
- guard(pcm_stream_lock_irq)(substream);
/* resume pause */
if (runtime->state == SNDRV_PCM_STATE_PAUSED)
snd_pcm_pause(substream, false);
--
2.55.0