* [PATCH] staging: greybus: audio: fix use-after-free in gbcodec_hw_params
@ 2026-10-05 6:01 Marinela Tatiana Selseth
2026-10-05 8:34 ` Johan Hovold
0 siblings, 1 reply; 2+ messages in thread
From: Marinela Tatiana Selseth @ 2026-10-05 6:01 UTC (permalink / raw)
To: vaibhav.sr, mgreer, johan, elder, gregkh
Cc: greybus-dev, linux-staging, linux-kernel, Marinela Tatiana Selseth
Automated semantic analysis via Coccinelle uncovered a use-after-free
vulnerability in gbcodec_hw_params() caused by accessing a list
iterator variable outside the loop boundary.
The routine walks through the codec module list using
'list_for_each_entry' to locate a matching data connection.
After the loop exits, the iterator pointer 'module' becomes
out-of-bounds. Attempting to pass this unmapped reference into
'to_gb_bundle()' down the line triggers a critical kernel panic.
Fix this flaw by introducing a dedicated copy 'allocated_module'.
Cache the matched pointer inside the loop block only when
'find_data()' returns a valid reference, and route the subsequent
power management execution steps safely through this verified object
tracking reference.
Assisted-by: Gemini
Signed-off-by: Marinela Tatiana Selseth <marinela.selseth@firmwaredesign.org>
---
drivers/staging/greybus/audio_codec.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/staging/greybus/audio_codec.c b/drivers/staging/greybus/audio_codec.c
index 6daa4e706792..a0645bf83097 100644
--- a/drivers/staging/greybus/audio_codec.c
+++ b/drivers/staging/greybus/audio_codec.c
@@ -396,6 +396,7 @@ static int gbcodec_hw_params(struct snd_pcm_substream *substream,
u8 sig_bits, channels;
u32 format, rate;
struct gbaudio_module_info *module;
+ struct gbaudio_module_info *allocated_module = NULL;
struct gbaudio_data_connection *data;
struct gb_bundle *bundle;
struct gbaudio_codec_info *codec = dev_get_drvdata(dai->dev);
@@ -439,8 +440,10 @@ static int gbcodec_hw_params(struct snd_pcm_substream *substream,
/* find the data connection */
list_for_each_entry(module, &codec->module_list, list) {
data = find_data(module, dai->id);
- if (data)
+ if (data) {
+ allocated_module = module;
break;
+ }
}
if (!data) {
@@ -456,7 +459,7 @@ static int gbcodec_hw_params(struct snd_pcm_substream *substream,
return -EINVAL;
}
- bundle = to_gb_bundle(module->dev);
+ bundle = to_gb_bundle(allocated_module->dev);
ret = gb_pm_runtime_get_sync(bundle);
if (ret) {
mutex_unlock(&codec->lock);
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] staging: greybus: audio: fix use-after-free in gbcodec_hw_params
2026-10-05 6:01 [PATCH] staging: greybus: audio: fix use-after-free in gbcodec_hw_params Marinela Tatiana Selseth
@ 2026-10-05 8:34 ` Johan Hovold
0 siblings, 0 replies; 2+ messages in thread
From: Johan Hovold @ 2026-10-05 8:34 UTC (permalink / raw)
To: Marinela Tatiana Selseth
Cc: vaibhav.sr, mgreer, elder, gregkh, greybus-dev, linux-staging,
linux-kernel
On Mon, Oct 05, 2026 at 01:01:26AM -0500, Marinela Tatiana Selseth wrote:
> Automated semantic analysis via Coccinelle uncovered a use-after-free
> vulnerability in gbcodec_hw_params() caused by accessing a list
> iterator variable outside the loop boundary.
>
> The routine walks through the codec module list using
> 'list_for_each_entry' to locate a matching data connection.
> After the loop exits, the iterator pointer 'module' becomes
> out-of-bounds. Attempting to pass this unmapped reference into
> 'to_gb_bundle()' down the line triggers a critical kernel panic.
>
> Fix this flaw by introducing a dedicated copy 'allocated_module'.
> Cache the matched pointer inside the loop block only when
> 'find_data()' returns a valid reference, and route the subsequent
> power management execution steps safely through this verified object
> tracking reference.
>
> Assisted-by: Gemini
> Signed-off-by: Marinela Tatiana Selseth <marinela.selseth@firmwaredesign.org>
> ---
> drivers/staging/greybus/audio_codec.c | 7 +++++--
> 1 file changed, 5 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/staging/greybus/audio_codec.c b/drivers/staging/greybus/audio_codec.c
> index 6daa4e706792..a0645bf83097 100644
> --- a/drivers/staging/greybus/audio_codec.c
> +++ b/drivers/staging/greybus/audio_codec.c
> @@ -396,6 +396,7 @@ static int gbcodec_hw_params(struct snd_pcm_substream *substream,
> u8 sig_bits, channels;
> u32 format, rate;
> struct gbaudio_module_info *module;
> + struct gbaudio_module_info *allocated_module = NULL;
> struct gbaudio_data_connection *data;
> struct gb_bundle *bundle;
> struct gbaudio_codec_info *codec = dev_get_drvdata(dai->dev);
> @@ -439,8 +440,10 @@ static int gbcodec_hw_params(struct snd_pcm_substream *substream,
> /* find the data connection */
> list_for_each_entry(module, &codec->module_list, list) {
> data = find_data(module, dai->id);
> - if (data)
> + if (data) {
> + allocated_module = module;
> break;
> + }
> }
>
> if (!data) {
The code bails out here when no data is found (and the function bails
out early when there are no modules), so how could module be out of
bounds below?
Again, don't send LLM assisted patches to staging which is used for people
to learn.
> @@ -456,7 +459,7 @@ static int gbcodec_hw_params(struct snd_pcm_substream *substream,
> return -EINVAL;
> }
>
> - bundle = to_gb_bundle(module->dev);
> + bundle = to_gb_bundle(allocated_module->dev);
> ret = gb_pm_runtime_get_sync(bundle);
> if (ret) {
> mutex_unlock(&codec->lock);
Johan
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 8:35 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 6:01 [PATCH] staging: greybus: audio: fix use-after-free in gbcodec_hw_params Marinela Tatiana Selseth
2026-10-05 8:34 ` Johan Hovold
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®