On Fri May 22 21:16:52 2026 +0530, Ashwin Gundarapu wrote:
> Add a null check for the dev pointer after retrieving it from
> the substream. Without this, a use-after-free or null pointer
> dereference can occur when closing the audio device, causing
> a kernel page fault.
> 
> Link: https://bugzilla.redhat.com/show_bug.cgi?id=2365068
> Signed-off-by: Ashwin Gundarapu <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/cx231xx/cx231xx-audio.c | 5 +++++
 1 file changed, 5 insertions(+)

---

diff --git a/drivers/media/usb/cx231xx/cx231xx-audio.c 
b/drivers/media/usb/cx231xx/cx231xx-audio.c
index 9c71b32552df..b24ceef497e4 100644
--- a/drivers/media/usb/cx231xx/cx231xx-audio.c
+++ b/drivers/media/usb/cx231xx/cx231xx-audio.c
@@ -443,6 +443,11 @@ static int snd_cx231xx_pcm_close(struct snd_pcm_substream 
*substream)
        int ret;
        struct cx231xx *dev = snd_pcm_substream_chip(substream);
 
+       if (!dev) {
+               pr_err("cx231xx: called with null device\n");
+               return -ENODEV;
+       }
+
        dev_dbg(dev->dev, "closing device\n");
 
        /* inform hardware to stop streaming */
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to