[syzbot] [sound?] BUG: unable to handle kernel NULL pointer dereference in snd_ctl_led_get

Jeffin Philip posted 1 patch 1 month ago
[syzbot] [sound?] BUG: unable to handle kernel NULL pointer dereference in snd_ctl_led_get
Posted by Jeffin Philip 1 month ago
#syz test: upstream 818bebeb63dd

diff --git a/sound/core/control_led.c b/sound/core/control_led.c
index 8cbacee57ce7..f6a46ed97d37 100644
--- a/sound/core/control_led.c
+++ b/sound/core/control_led.c
@@ -114,13 +114,11 @@ static int snd_ctl_led_get(struct snd_ctl_led_ctl *lctl)
        info.id = kctl->id;
        info.id.index += lctl->index_offset;
        info.id.numid += lctl->index_offset;
-       result = kctl->info(kctl, &info);
-       if (result < 0)
+       if (!kctl->info || kctl->info(kctl, &info))
                return -1;
        memset(&value, 0, sizeof(value));
        value.id = info.id;
-       result = kctl->get(kctl, &value);
-       if (result < 0)
+       if (!kctl->get || kctl->get(kctl, &value))
                return -1;
        if (info.type == SNDRV_CTL_ELEM_TYPE_BOOLEAN ||
            info.type == SNDRV_CTL_ELEM_TYPE_INTEGER) {
Re: [syzbot] [sound?] BUG: unable to handle kernel NULL pointer dereference in snd_ctl_led_get
Posted by syzbot 1 month ago
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+b7fe2760ea6f1ee44b4d@syzkaller.appspotmail.com
Tested-by: syzbot+b7fe2760ea6f1ee44b4d@syzkaller.appspotmail.com

Tested on:

commit:         818bebeb drm/xe: Don't hand out the flat CCS storage a..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=16e14579580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=ccca94d2c01b9e78
dashboard link: https://syzkaller.appspot.com/bug?extid=b7fe2760ea6f1ee44b4d
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch:          https://syzkaller.appspot.com/x/patch.diff?x=1714e579580000

Note: testing is done by a robot and is best-effort only.