[PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments
From: Takashi Iwai
Date: Thu Oct 08 2026 - 15:31:06 EST
When a creation of input or output compress-offload task fails in
fsl-asrc driver, the task->input or task->output pointer is left with
ERR_PTR(), which is non-NULL. Then it's handled in the compress
offload core and it tries to release via dma_buf_put(), resulting in
an access to a wrong address.
Clear the bogus pointers properly before returning an error.
Fixes: 24a01710f627 ("ASoC: fsl_asrc_m2m: Add memory to memory function")
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Signed-off-by: Takashi Iwai <tiwai@xxxxxxx>
---
sound/soc/fsl/fsl_asrc_m2m.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/soc/fsl/fsl_asrc_m2m.c b/sound/soc/fsl/fsl_asrc_m2m.c
index 4bc40f328f58..42b0e21f281c 100644
--- a/sound/soc/fsl/fsl_asrc_m2m.c
+++ b/sound/soc/fsl/fsl_asrc_m2m.c
@@ -475,6 +475,7 @@ static int fsl_asrc_m2m_comp_task_create(struct snd_compr_stream *stream,
task->input = dma_buf_export(&exp_info_in);
if (IS_ERR(task->input)) {
ret = PTR_ERR(task->input);
+ task->input = NULL;
return ret;
}
@@ -485,6 +486,7 @@ static int fsl_asrc_m2m_comp_task_create(struct snd_compr_stream *stream,
task->output = dma_buf_export(&exp_info_out);
if (IS_ERR(task->output)) {
ret = PTR_ERR(task->output);
+ task->output = NULL;
return ret;
}
--
2.55.0