Re: [PATCH 2/2] ALSA: caiaq: unregister the input device when probe fails

From: Takashi Iwai

Date: Mon Sep 28 2026 - 07:59:40 EST


On Fri, 25 Sep 2026 19:07:17 +0200,
Nguyen Ngoc Thang wrote:
>
> setup_card() registers the input device, whose name and phys point into
> struct snd_usb_caiaqdev, and then goes on to snd_card_register() and
> snd_usb_caiaq_control_init(). If either fails, snd_probe() calls
> snd_card_free(), which frees the device state but leaves the input
> device registered: card_free() only clears the pointer, and the input
> device is unregistered from snd_disconnect() alone. Reading its "uevent"
> attribute afterwards dereferences freed memory:
>
> BUG: KASAN: slab-use-after-free in string+0x4a9/0x4f0
> Read of size 1 at addr ffff8880208f5043 by task caiaq/4967
> add_uevent_var+0x183/0x3a0
> input_dev_uevent+0x162/0x900
> dev_uevent+0x2f1/0x870
> uevent_show+0x1ca/0x3a0
> ...
>
> Unregister the input device on the probe error path, as
> snd_disconnect() does. snd_usb_caiaq_input_disconnect() is a no-op when
> no input device was registered.
>
> Reproduced with a raw-gadget Audio Kontrol 1 and a temporary hack that
> makes snd_usb_caiaq_control_init() fail.
>
> Fixes: 28abd224db4a ("ALSA: caiaq: Handle probe errors properly")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: syzbot+2a123f6269da57ffefaa@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=2a123f6269da57ffefaa
> Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@xxxxxxxxx>

Applied now. Thanks.


Takashi