On Mon Jul 6 16:24:06 2026 -0400, Shuangpeng Bai wrote:
> The ALSA PCM callbacks store the driver state in pcm->private_data. An
> open PCM file can outlive USB disconnect because usbtv_audio_free() uses
> snd_card_free_when_closed(). The disconnect path can then drop the V4L2
> device reference and free struct usbtv before ALSA releases the substream,
> so a later close dereferences freed memory in snd_usbtv_pcm_close().
>
> Take a V4L2 device reference for the ALSA card and drop it from the card
> private_free callback. This keeps struct usbtv valid until ALSA has closed
> the remaining files and freed the card.
>
> Closes:
> https://lore.kernel.org/r/[email protected]
> Fixes: 63ddf68de52e ("[media] usbtv: add audio support")
> Cc: [email protected]
> Signed-off-by: Shuangpeng Bai <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/usb/usbtv/usbtv-audio.c | 11 +++++++++++
1 file changed, 11 insertions(+)
---
diff --git a/drivers/media/usb/usbtv/usbtv-audio.c
b/drivers/media/usb/usbtv/usbtv-audio.c
index 333bd305a4f9..ae0a14e5ed2a 100644
--- a/drivers/media/usb/usbtv/usbtv-audio.c
+++ b/drivers/media/usb/usbtv/usbtv-audio.c
@@ -317,6 +317,13 @@ static const struct snd_pcm_ops snd_usbtv_pcm_ops = {
.pointer = snd_usbtv_pointer,
};
+static void usbtv_audio_card_free(struct snd_card *card)
+{
+ struct usbtv *usbtv = card->private_data;
+
+ v4l2_device_put(&usbtv->v4l2_dev);
+}
+
int usbtv_audio_init(struct usbtv *usbtv)
{
int rv;
@@ -331,6 +338,10 @@ int usbtv_audio_init(struct usbtv *usbtv)
if (rv < 0)
return rv;
+ v4l2_device_get(&usbtv->v4l2_dev);
+ card->private_data = usbtv;
+ card->private_free = usbtv_audio_card_free;
+
strscpy(card->driver, usbtv->dev->driver->name, sizeof(card->driver));
strscpy(card->shortname, "usbtv", sizeof(card->shortname));
snprintf(card->longname, sizeof(card->longname),
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]