Re: [PATCH] ALSA: ump: Fix double-free of ump->out_cvts on legacy rawmidi attach failure
From: syzbot
Date: Tue Jul 28 2026 - 20:23:22 EST
> #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master
This crash does not have a reproducer. I cannot test it.
>
> If snd_rawmidi_new() fails inside snd_ump_attach_legacy_rawmidi(), the
> error path frees ump->out_cvts but leaves the pointer dangling. Since
> ump->out_cvts is a field of the long-lived struct snd_ump_endpoint
> (not the rawmidi device that failed to be created), it gets freed a
> second time later during normal endpoint teardown, in
> snd_ump_endpoint_free(), invoked via snd_rawmidi_free()'s
> private_free callback when the sound card is released. This results
> in a KASAN double-free/invalid-free.
>
> Clear ump->out_cvts to NULL after freeing it on the error path, so
> the later unconditional kfree() in snd_ump_endpoint_free() becomes a
> harmless no-op.
>
> Reported-by: syzbot+b6cab840e6a85641c7ad@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=b6cab840e6a85641c7ad
> Signed-off-by: Deepanshu Kartikey <kartikey406@xxxxxxxxx>
> ---
> sound/core/ump.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/sound/core/ump.c b/sound/core/ump.c
> index 70520c7ca293..632c13baf21e 100644
> --- a/sound/core/ump.c
> +++ b/sound/core/ump.c
> @@ -1365,6 +1365,7 @@ int snd_ump_attach_legacy_rawmidi(struct snd_ump_endpoint *ump,
> &rmidi);
> if (err < 0) {
> kfree(ump->out_cvts);
> + ump->out_cvts = NULL;
> return err;
> }
>
> --
> 2.43.0
>