On Wed Jul 8 22:33:38 2026 +0800, Ruoyu Wang wrote:
> snd_cobalt_card_create() stores cobsc in sc->private_data and installs
> snd_cobalt_card_private_free() as sc->private_free. From that point,
> snd_card_free(sc) releases cobsc through the ALSA card cleanup path.
> 
> If cobalt_alsa_init() fails after snd_cobalt_card_create(), the
> err_exit_free path calls snd_card_free(sc) and then kfree(cobsc). That
> second free releases the same object again.
> 
> Remove the explicit kfree(cobsc) and leave ownership with the ALSA card.
> 
> This issue was found by a static analysis checker and confirmed by
> manual source review.
> 
> Fixes: 85756a069c55 ("[media] cobalt: add new driver")
> Cc: [email protected]
> Signed-off-by: Ruoyu Wang <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/pci/cobalt/cobalt-alsa-main.c | 1 -
 1 file changed, 1 deletion(-)

---

diff --git a/drivers/media/pci/cobalt/cobalt-alsa-main.c 
b/drivers/media/pci/cobalt/cobalt-alsa-main.c
index 7bb7f13c70c0..9ed547cd40af 100644
--- a/drivers/media/pci/cobalt/cobalt-alsa-main.c
+++ b/drivers/media/pci/cobalt/cobalt-alsa-main.c
@@ -135,7 +135,6 @@ int cobalt_alsa_init(struct cobalt_stream *s)
 err_exit_free:
        if (sc != NULL)
                snd_card_free(sc);
-       kfree(cobsc);
 err_exit:
        return ret;
 }
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to