[PATCH 2/2] ALSA: control: Fix UAF in snd_ctl_elem_add() on card disconnect
From: Takashi Iwai
Date: Tue Sep 29 2026 - 08:59:45 EST
A use-after-free can be triggered via SNDRV_CTL_IOCTL_ELEM_ADD when a
USB audio card is disconnected while an ELEM_ADD ioctl is in flight.
The reproducer parks the ioctl thread inside copy_from_user() using
userfaultfd, then tears down the USB device. Unlike every other
ALSA control _user handler (ELEM_INFO, ELEM_READ, ELEM_WRITE, TLV_*),
snd_ctl_elem_add_user() never calls snd_power_ref_and_wait(), so the
parked thread holds no power reference. snd_card_disconnect() therefore
cannot observe it via snd_power_sync_ref() and proceeds unimpeded:
1. card->shutdown is set to 1
2. device_del(&card->card_dev) drops the kobject reference on the
parent USB interface device (card->dev = &intf->dev)
3. The USB core drops its own reference and calls device_release(),
freeing the struct usb_interface, including the embedded struct
device that card->dev points to
When the userfaultfd is resolved and the thread resumes,
snd_ctl_elem_add() acquires controls_rwsem without checking
card->shutdown and calls __snd_ctl_add_replace(). Because the
reproducer pre-registered the same control, the CTL_ADD_EXCLUSIVE
path calls dev_err(card->dev, ...) on the freed USB interface:
KASAN: slab-use-after-free Read in __dev_printk
Add a card->shutdown guard immediately after acquiring controls_rwsem
in snd_ctl_elem_add(). At that point card->shutdown is guaranteed to
be stable: snd_card_disconnect() sets it before freeing the parent
device, and it never transitions back to 0. A thread that acquired
the lock before disconnect sees shutdown=0 and holds the write lock
through the rest of the operation, preventing concurrent disconnect
from proceeding past its own controls_rwsem-less shutdown=1 store
(which happened earlier, outside the lock) from racing with dev_err().
Reported-by: Farhad Alemi <farhad.alemi@xxxxxxxxxxxx>
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Takashi Iwai <tiwai@xxxxxxx>
---
sound/core/control.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/core/control.c b/sound/core/control.c
index 4199342d4ffe..535ceba294ac 100644
--- a/sound/core/control.c
+++ b/sound/core/control.c
@@ -1802,6 +1802,8 @@ static int snd_ctl_elem_add(struct snd_ctl_file *file,
alloc_size = compute_user_elem_size(private_size, count);
guard(rwsem_write)(&card->controls_rwsem);
+ if (card->shutdown)
+ return -ENODEV;
if (check_user_elem_overflow(card, alloc_size))
return -ENOMEM;
--
2.55.0