From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751496AbcIBNNt (ORCPT ); Fri, 2 Sep 2016 09:13:49 -0400 Received: from mx2.suse.de ([195.135.220.15]:32913 "EHLO mx2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750859AbcIBNNr (ORCPT ); Fri, 2 Sep 2016 09:13:47 -0400 Date: Fri, 02 Sep 2016 15:13:45 +0200 Message-ID: From: Takashi Iwai To: Vegard Nossum Cc: Jaroslav Kysela , alsa-devel@alsa-project.org, syzkaller , linux-kernel@vger.kernel.org Subject: Re: [PATCH 1/3] ALSA: timer: fix NULL pointer dereference in read()/ioctl() race In-Reply-To: <14739ff0-b415-08e5-5f5c-a29a99fe473e@oracle.com> References: <20160828223351.32489-1-vegard.nossum@oracle.com> <0560accf-2461-8205-6377-32b464bfce7e@oracle.com> <14739ff0-b415-08e5-5f5c-a29a99fe473e@oracle.com> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI/1.14.6 (Maruoka) FLIM/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL/10.8 Emacs/24.5 (x86_64-suse-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka") Content-Type: text/plain; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, 02 Sep 2016 14:34:47 +0200, Vegard Nossum wrote: > > On 08/29/2016 09:14 AM, Vegard Nossum wrote: > > On 08/29/2016 09:02 AM, Takashi Iwai wrote: > >> On Mon, 29 Aug 2016 00:33:49 +0200, > >> Vegard Nossum wrote: > >>> @@ -1602,15 +1602,25 @@ static int snd_timer_user_tselect(struct file > >>> *file, > >>> kfree(tu->tqueue); > >>> tu->tqueue = NULL; > >>> if (tu->tread) { > >>> - tu->tqueue = kmalloc(tu->queue_size * sizeof(struct > >>> snd_timer_tread), > >>> + struct snd_timer_tread *ttr; > >>> + ttr = kmalloc(tu->queue_size * sizeof(struct snd_timer_tread), > >>> GFP_KERNEL); > >>> - if (tu->tqueue == NULL) > >>> + if (ttr) { > >>> + kfree(tu->tqueue); > >>> + tu->tqueue = ttr; > >> > >> This looks like the double-tree, as you didn't remove the kfree() call > >> in the above. But, I guess this change is superfluous when you > >> introduce the mutex at... > > > > You're right, this hunk is garbage. > > > > Please see the new patch (attached), I also changed the patch > > description slightly to match the changes. > > > > I'll start running some tests on the new patch. > > I tested the new patch (from the email I'm replying to). It seems to > work for me. OK, queued now. Thanks! Takashi