Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1345742 > unrolled thread

[PATCH] ALSA: mts64: fix NULL pointer dereference

Started bySudip Mukherjee <sudipm.mukherjee@gmail.com>
First post2016-02-29 13:20 +0100
Last post2016-02-29 17:30 +0100
Articles 3 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] ALSA: mts64: fix NULL pointer dereference Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2016-02-29 13:20 +0100
    Re: [PATCH] ALSA: mts64: fix NULL pointer dereference Takashi Iwai <tiwai@suse.de> - 2016-02-29 13:30 +0100
      Re: [PATCH] ALSA: mts64: fix NULL pointer dereference Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2016-02-29 17:30 +0100

#1345742 — [PATCH] ALSA: mts64: fix NULL pointer dereference

FromSudip Mukherjee <sudipm.mukherjee@gmail.com>
Date2016-02-29 13:20 +0100
Subject[PATCH] ALSA: mts64: fix NULL pointer dereference
Message-ID<r7uXU-2SL-11@gated-at.bofh.it>
While registering pardev, the irq_func was also registered. As a
result when we tried to probe for the card, an interrupt was generated
and in the ISR we tried to dereference private_data. But private_data
is still NULL as we have not yet done snd_mts64_create(). Lets probe
for the card after mts64 is created.

Reported-by: Fengguang Wu <fengguang.wu@intel.com>
Fixes: 94a573500d48 ("ALSA: mts64: use new parport device model")
Signed-off-by: Sudip Mukherjee <sudip.mukherjee@codethink.co.uk>
---
 sound/drivers/mts64.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/sound/drivers/mts64.c b/sound/drivers/mts64.c
index c76bd87..fd4d18d 100644
--- a/sound/drivers/mts64.c
+++ b/sound/drivers/mts64.c
@@ -964,11 +964,6 @@ static int snd_mts64_probe(struct platform_device *pdev)
 		err = -EIO;
 		goto free_pardev;
 	}
-	err = mts64_probe(p);
-	if (err) {
-		err = -EIO;
-		goto release_pardev;
-	}
 
 	if ((err = snd_mts64_create(card, pardev, &mts)) < 0) {
 		snd_printd("Cannot create main component\n");
@@ -976,6 +971,12 @@ static int snd_mts64_probe(struct platform_device *pdev)
 	}
 	card->private_data = mts;
 	card->private_free = snd_mts64_card_private_free;
+
+	err = mts64_probe(p);
+	if (err) {
+		err = -EIO;
+		goto __err;
+	}
 	
 	if ((err = snd_mts64_rawmidi_create(card)) < 0) {
 		snd_printd("Creating Rawmidi component failed\n");
-- 
1.9.1

[toc] | [next] | [standalone]


#1345750

FromTakashi Iwai <tiwai@suse.de>
Date2016-02-29 13:30 +0100
Message-ID<r7v7B-2Wa-33@gated-at.bofh.it>
In reply to#1345742
On Mon, 29 Feb 2016 13:13:30 +0100,
Sudip Mukherjee wrote:
> 
> While registering pardev, the irq_func was also registered. As a
> result when we tried to probe for the card, an interrupt was generated
> and in the ISR we tried to dereference private_data. But private_data
> is still NULL as we have not yet done snd_mts64_create(). Lets probe
> for the card after mts64 is created.
> 
> Reported-by: Fengguang Wu <fengguang.wu@intel.com>
> Fixes: 94a573500d48 ("ALSA: mts64: use new parport device model")
> Signed-off-by: Sudip Mukherjee <sudip.mukherjee@codethink.co.uk>

Applied, thanks.


Takashi

> ---
>  sound/drivers/mts64.c | 11 ++++++-----
>  1 file changed, 6 insertions(+), 5 deletions(-)
> 
> diff --git a/sound/drivers/mts64.c b/sound/drivers/mts64.c
> index c76bd87..fd4d18d 100644
> --- a/sound/drivers/mts64.c
> +++ b/sound/drivers/mts64.c
> @@ -964,11 +964,6 @@ static int snd_mts64_probe(struct platform_device *pdev)
>  		err = -EIO;
>  		goto free_pardev;
>  	}
> -	err = mts64_probe(p);
> -	if (err) {
> -		err = -EIO;
> -		goto release_pardev;
> -	}
>  
>  	if ((err = snd_mts64_create(card, pardev, &mts)) < 0) {
>  		snd_printd("Cannot create main component\n");
> @@ -976,6 +971,12 @@ static int snd_mts64_probe(struct platform_device *pdev)
>  	}
>  	card->private_data = mts;
>  	card->private_free = snd_mts64_card_private_free;
> +
> +	err = mts64_probe(p);
> +	if (err) {
> +		err = -EIO;
> +		goto __err;
> +	}
>  	
>  	if ((err = snd_mts64_rawmidi_create(card)) < 0) {
>  		snd_printd("Creating Rawmidi component failed\n");
> -- 
> 1.9.1
> 
> 

[toc] | [prev] | [next] | [standalone]


#1345962

FromSudip Mukherjee <sudipm.mukherjee@gmail.com>
Date2016-02-29 17:30 +0100
Message-ID<r7yRQ-5oO-15@gated-at.bofh.it>
In reply to#1345750
On Mon, Feb 29, 2016 at 01:24:24PM +0100, Takashi Iwai wrote:
> On Mon, 29 Feb 2016 13:13:30 +0100,
> Sudip Mukherjee wrote:
> > 
> > While registering pardev, the irq_func was also registered. As a
> > result when we tried to probe for the card, an interrupt was generated
> > and in the ISR we tried to dereference private_data. But private_data
> > is still NULL as we have not yet done snd_mts64_create(). Lets probe
> > for the card after mts64 is created.
> > 
> > Reported-by: Fengguang Wu <fengguang.wu@intel.com>
> > Fixes: 94a573500d48 ("ALSA: mts64: use new parport device model")
> > Signed-off-by: Sudip Mukherjee <sudip.mukherjee@codethink.co.uk>
> 
> Applied, thanks.

Thanks, I will wait for one day for any report from 0day and then send
you the similar patch for portman.

BTW, i lost that auction of portman.

regards
sudip

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web