Re: [PATCH] ALSA: hda: Avoid dev_err() at probe error in vga_switcheroo handler
From: Takashi Iwai
Date: Wed Oct 07 2026 - 18:20:31 EST
On Wed, 07 Oct 2026 23:37:25 +0200,
Takashi Iwai wrote:
>
> The vga_switcheroo handler azx_vs_set_state() calls
> azx_probe_contine() for enabling the audio, and if an error happens
> during the probe, azx_probe_continue() releases its associated sound
> card object at the error path. In return, azx_vs_set_state() tries to
> show an error via dev_err() with the card's device pointer, but since
> the card object is already gone, this can lead to a UAF.
>
> For avoiding the unneeded crash, replace the device for the error
> message with the original PCI device that is passed to
> azx_vx_set_state() itself.
>
> Fixes: 39173303c838 ("ALSA: hda: Free card instance properly at probe errors")
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Signed-off-by: Takashi Iwai <tiwai@xxxxxxx>
Scratch this one. It turned out that this is no fundamental fix
(although the change doesn't hurt), and we'd see a more serious
deadlock if this scenario really happens.
Will submit a better fix instead.
Takashi