| From a7f45c358a6fe98f1a9dc8e528e4eff0353021b2 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 31 May 2024 13:08:20 +0100 |
| Subject: ALSA: hda: cs35l41: Possible null pointer dereference in |
| cs35l41_hda_unbind() |
| |
| From: Simon Trimmer <simont@opensource.cirrus.com> |
| |
| [ Upstream commit 6386682cdc8b41319c92fbbe421953e33a28840c ] |
| |
| The cs35l41_hda_unbind() function clears the hda_component entry |
| matching it's index and then dereferences the codec pointer held in the |
| first element of the hda_component array, this is an issue when the |
| device index was 0. |
| |
| Instead use the codec pointer stashed in the cs35l41_hda structure as it |
| will still be valid. |
| |
| Fixes: 7cf5ce66dfda ("ALSA: hda: cs35l41: Add device_link between HDA and cs35l41_hda") |
| Signed-off-by: Simon Trimmer <simont@opensource.cirrus.com> |
| Link: https://lore.kernel.org/r/20240531120820.35367-1-simont@opensource.cirrus.com |
| Signed-off-by: Takashi Iwai <tiwai@suse.de> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| sound/pci/hda/cs35l41_hda.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/sound/pci/hda/cs35l41_hda.c b/sound/pci/hda/cs35l41_hda.c |
| index 3c157b006a5a2..b437beae9b516 100644 |
| --- a/sound/pci/hda/cs35l41_hda.c |
| +++ b/sound/pci/hda/cs35l41_hda.c |
| @@ -1187,7 +1187,7 @@ static void cs35l41_hda_unbind(struct device *dev, struct device *master, void * |
| if (comps[cs35l41->index].dev == dev) { |
| memset(&comps[cs35l41->index], 0, sizeof(*comps)); |
| sleep_flags = lock_system_sleep(); |
| - device_link_remove(&comps->codec->core.dev, cs35l41->dev); |
| + device_link_remove(&cs35l41->codec->core.dev, cs35l41->dev); |
| unlock_system_sleep(sleep_flags); |
| } |
| } |
| -- |
| 2.43.0 |
| |