Patch "ALSA: hda - fix use-after-free after module unload" has been added to the 4.6-stable tree
From: <gregkh@linuxfoundation.org>
Date: 2016-07-25 00:30:53
This is a note to let you know that I've just added the patch titled
ALSA: hda - fix use-after-free after module unload
to the 4.6-stable tree which can be found at:
http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary
The filename of the patch is:
alsa-hda-fix-use-after-free-after-module-unload.patch
and it can be found in the queue-4.6 subdirectory.
If you, or anyone else, feels it should not be added to the stable tree,
please let [off-list ref] know about it.
From ab58d8cc870ef3f0771c197700441936898d1f1d Mon Sep 17 00:00:00 2001
From: Peter Wu <redacted>
Date: Mon, 11 Jul 2016 19:51:06 +0200
Subject: ALSA: hda - fix use-after-free after module unload
From: Peter Wu <redacted>
commit ab58d8cc870ef3f0771c197700441936898d1f1d upstream.
register_vga_switcheroo() sets the PM ops from the hda structure which
is freed later in azx_free. Make sure that these ops are cleared.
Caught by KASAN, initially noticed due to a general protection fault.
Fixes: 246efa4a072f ("snd/hda: add runtime suspend/resume on optimus support (v4)")
Signed-off-by: Peter Wu <redacted>
Signed-off-by: Takashi Iwai <redacted>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/pci/hda/hda_intel.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/sound/pci/hda/hda_intel.c
+++ b/sound/pci/hda/hda_intel.c@@ -1218,8 +1218,10 @@ static int azx_free(struct azx *chip) if (use_vga_switcheroo(hda)) { if (chip->disabled && hda->probe_continued) snd_hda_unlock_devices(&chip->bus); - if (hda->vga_switcheroo_registered) + if (hda->vga_switcheroo_registered) { vga_switcheroo_unregister_client(chip->pci); + vga_switcheroo_fini_domain_pm_ops(chip->card->dev); + } } if (bus->chip_init) {
Patches currently in stable-queue which might be from peter@lekensteyn.nl are queue-4.6/alsa-hda-fix-use-after-free-after-module-unload.patch