On Fri May 22 21:16:52 2026 +0530, Ashwin Gundarapu wrote:
> Add a null check for the dev pointer after retrieving it from
> the substream. Without this, a use-after-free or null pointer
> dereference can occur when closing the audio device, causing
> a kernel page fault.
>
> Link: https://bugzilla.redhat.com/show_bug.cgi?id=2365068
> Signed-off-by: Ashwin Gundarapu <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/usb/cx231xx/cx231xx-audio.c | 5 +++++
1 file changed, 5 insertions(+)
---
diff --git a/drivers/media/usb/cx231xx/cx231xx-audio.c
b/drivers/media/usb/cx231xx/cx231xx-audio.c
index 9c71b32552df..b24ceef497e4 100644
--- a/drivers/media/usb/cx231xx/cx231xx-audio.c
+++ b/drivers/media/usb/cx231xx/cx231xx-audio.c
@@ -443,6 +443,11 @@ static int snd_cx231xx_pcm_close(struct snd_pcm_substream
*substream)
int ret;
struct cx231xx *dev = snd_pcm_substream_chip(substream);
+ if (!dev) {
+ pr_err("cx231xx: called with null device\n");
+ return -ENODEV;
+ }
+
dev_dbg(dev->dev, "closing device\n");
/* inform hardware to stop streaming */
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]