On Mon Jul 6 16:24:06 2026 -0400, Shuangpeng Bai wrote:
> The ALSA PCM callbacks store the driver state in pcm->private_data. An
> open PCM file can outlive USB disconnect because usbtv_audio_free() uses
> snd_card_free_when_closed(). The disconnect path can then drop the V4L2
> device reference and free struct usbtv before ALSA releases the substream,
> so a later close dereferences freed memory in snd_usbtv_pcm_close().
> 
> Take a V4L2 device reference for the ALSA card and drop it from the card
> private_free callback. This keeps struct usbtv valid until ALSA has closed
> the remaining files and freed the card.
> 
> Closes: 
> https://lore.kernel.org/r/[email protected]
> Fixes: 63ddf68de52e ("[media] usbtv: add audio support")
> Cc: [email protected]
> Signed-off-by: Shuangpeng Bai <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/usbtv/usbtv-audio.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

---

diff --git a/drivers/media/usb/usbtv/usbtv-audio.c 
b/drivers/media/usb/usbtv/usbtv-audio.c
index 333bd305a4f9..ae0a14e5ed2a 100644
--- a/drivers/media/usb/usbtv/usbtv-audio.c
+++ b/drivers/media/usb/usbtv/usbtv-audio.c
@@ -317,6 +317,13 @@ static const struct snd_pcm_ops snd_usbtv_pcm_ops = {
        .pointer = snd_usbtv_pointer,
 };
 
+static void usbtv_audio_card_free(struct snd_card *card)
+{
+       struct usbtv *usbtv = card->private_data;
+
+       v4l2_device_put(&usbtv->v4l2_dev);
+}
+
 int usbtv_audio_init(struct usbtv *usbtv)
 {
        int rv;
@@ -331,6 +338,10 @@ int usbtv_audio_init(struct usbtv *usbtv)
        if (rv < 0)
                return rv;
 
+       v4l2_device_get(&usbtv->v4l2_dev);
+       card->private_data = usbtv;
+       card->private_free = usbtv_audio_card_free;
+
        strscpy(card->driver, usbtv->dev->driver->name, sizeof(card->driver));
        strscpy(card->shortname, "usbtv", sizeof(card->shortname));
        snprintf(card->longname, sizeof(card->longname),
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to