On Wed Jul 8 22:33:38 2026 +0800, Ruoyu Wang wrote:
> snd_cobalt_card_create() stores cobsc in sc->private_data and installs
> snd_cobalt_card_private_free() as sc->private_free. From that point,
> snd_card_free(sc) releases cobsc through the ALSA card cleanup path.
>
> If cobalt_alsa_init() fails after snd_cobalt_card_create(), the
> err_exit_free path calls snd_card_free(sc) and then kfree(cobsc). That
> second free releases the same object again.
>
> Remove the explicit kfree(cobsc) and leave ownership with the ALSA card.
>
> This issue was found by a static analysis checker and confirmed by
> manual source review.
>
> Fixes: 85756a069c55 ("[media] cobalt: add new driver")
> Cc: [email protected]
> Signed-off-by: Ruoyu Wang <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/pci/cobalt/cobalt-alsa-main.c | 1 -
1 file changed, 1 deletion(-)
---
diff --git a/drivers/media/pci/cobalt/cobalt-alsa-main.c
b/drivers/media/pci/cobalt/cobalt-alsa-main.c
index 7bb7f13c70c0..9ed547cd40af 100644
--- a/drivers/media/pci/cobalt/cobalt-alsa-main.c
+++ b/drivers/media/pci/cobalt/cobalt-alsa-main.c
@@ -135,7 +135,6 @@ int cobalt_alsa_init(struct cobalt_stream *s)
err_exit_free:
if (sc != NULL)
snd_card_free(sc);
- kfree(cobsc);
err_exit:
return ret;
}
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]