Re: [PATCH] ALSA: pcm: set timer->private_data before registering the PCM timer

From: Takashi Iwai

Date: Sun Sep 13 2026 - 12:44:04 EST


On Sun, 13 Sep 2026 15:44:46 +0200,
Nguyen Ngoc Thang wrote:
>
> snd_pcm_timer_init() calls snd_device_register() to link the new
> struct snd_timer into the global timer list while it still carries
> hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),
> and only afterwards sets timer->private_data = substream.
>
> Once the timer is on the list under register_mutex, a concurrent
> reader can already reach it through the same mutex and invoke these
> callbacks. /proc/asound/timers does this via c_resolution(), and
> snd_timer_open()+snd_timer_start() reach start()/stop() the same way.
> All three dereference timer->private_data, which for this brief
> window is NULL, giving a NULL-pointer dereference:
>
> substream = timer->private_data;
> return substream->runtime ? ... // substream is NULL
>
> Move the private_data/private_free assignment before
> snd_device_register() so the timer is never visible on the list
> without its private_data set. On the snd_device_register() failure
> path, private_free() (snd_pcm_timer_free()) can now run, but it only
> does substream->timer = NULL, which is already NULL at that point
> since substream->timer is set to the new timer just once, after a
> successful registration -- so the failure path stays safe.
>
> Reported-by: syzbot+19da64013c46df87f971@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=19da64013c46df87f971
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@xxxxxxxxx>

Applied now. Thanks.


Takashi