mirror of
https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10.git
synced 2026-09-09 00:07:04 +08:00
ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
JIRA: https://issues.redhat.com/browse/RHEL-183295 commit 88fe2e3658726cb21ff2dcf9770bf672f9b9d31b Author: Ji'an Zhou <eilaimemedsnaimel@gmail.com> Date: Thu Jun 4 14:25:59 2026 +0000 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams snd_pcm_drain() uses init_waitqueue_entry which does not clear entry.prev/next, and add_wait_queue with a conditional remove_wait_queue that is skipped when to_check is no longer in the group after concurrent UNLINK. The orphaned wait entry remains on the unlinked substream sleep queue. On the next drain iteration, add_wait_queue adds the entry to a new queue while still linked on the old one, corrupting both lists. A subsequent wake_up dereferences NULL at the func pointer (mapped from the spinlock at offset 0 of the misinterpreted wait_queue_head_t), causing a kernel panic. Replace init_waitqueue_entry/add_wait_queue/conditional remove_wait_queue with init_wait_entry/prepare_to_wait/ finish_wait. init_wait_entry clears prev/next via INIT_LIST_HEAD on each iteration and sets autoremove_wake_function which auto-removes the entry on wake-up. finish_wait safely handles both the already-removed and still-queued cases. Fixes: 9b1dbd69ba6f ("ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain") Signed-off-by: Ji'an Zhou <eilaimemedsnaimel@gmail.com> Link: https://patch.msgid.link/20260604142559.3840881-1-eilaimemedsnaimel@gmail.com Signed-off-by: Takashi Iwai <tiwai@suse.de> Signed-off-by: Jaroslav Kysela <jkysela@redhat.com>
This commit is contained in:
@@ -2199,9 +2199,8 @@ static int snd_pcm_drain(struct snd_pcm_substream *substream,
|
||||
drain_no_period_wakeup = to_check->no_period_wakeup;
|
||||
drain_rate = to_check->rate;
|
||||
drain_bufsz = to_check->buffer_size;
|
||||
init_waitqueue_entry(&wait, current);
|
||||
set_current_state(TASK_INTERRUPTIBLE);
|
||||
add_wait_queue(&to_check->sleep, &wait);
|
||||
init_wait_entry(&wait, 0);
|
||||
prepare_to_wait(&to_check->sleep, &wait, TASK_INTERRUPTIBLE);
|
||||
snd_pcm_stream_unlock_irq(substream);
|
||||
if (drain_no_period_wakeup)
|
||||
tout = MAX_SCHEDULE_TIMEOUT;
|
||||
@@ -2219,7 +2218,7 @@ static int snd_pcm_drain(struct snd_pcm_substream *substream,
|
||||
group = snd_pcm_stream_group_ref(substream);
|
||||
snd_pcm_group_for_each_entry(s, substream) {
|
||||
if (s->runtime == to_check) {
|
||||
remove_wait_queue(&to_check->sleep, &wait);
|
||||
finish_wait(&to_check->sleep, &wait);
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user