From nobody Sat Jul 25 20:07:52 2026 Received: from mail-ed1-f50.google.com (mail-ed1-f50.google.com [209.85.208.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9C1CD3F9278 for ; Tue, 14 Jul 2026 08:29:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784017785; cv=none; b=qXcLMe+J86xJw3B+EsHtndoH+YbVJdDhelR5ZuHUFOCVqX2/Po1ubcUPO5adPZQX+1iRDsz9bI4b2cYI5/f/0juigPEgXIdtU/ZvQMvDllUk4U0L1XoGhrmX4wmJfmAMwYvyo6/fetPU1lEn9UTBkRbXRMtUXek+i63pjEcewKM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784017785; c=relaxed/simple; bh=hzylLn5H+WpEY/l1g0SAe/A9fRmocelN5I+yIjF5SWQ=; h=From:Content-Type:Mime-Version:Subject:Message-Id:Date:Cc:To; b=FszOzxiCyp0aWm/plMozSgTyxMaV9e0UpnG1XUSFLTQjd4JOmu1FzC6jAK0wM2IfQ1DKQiKFDJQOOkKWUgeM3xFqVShuTgGTuDdKjuz24C62e9oAtfBMl/mBGJhH4Cg7ap2eDAoy8muURWh4vHmfORvOgmSjbzRaLXeCpIQ0TrY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=IE024rIJ; arc=none smtp.client-ip=209.85.208.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="IE024rIJ" Received: by mail-ed1-f50.google.com with SMTP id 4fb4d7f45d1cf-697de23bd7dso928376a12.1 for ; Tue, 14 Jul 2026 01:29:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1784017775; x=1784622575; darn=vger.kernel.org; h=to:cc:date:message-id:subject:mime-version :content-transfer-encoding:content-type:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=O5qcr43MYyk8Rdnv8NoBGU4eaKU8JCviUqurIFf1yFI=; b=IE024rIJCnngw38LO5pE0E1fEGN7sNXA3gCpnC0QpD9CDskpikHQltr0JVDpHRHxUb ZQA1iKUMd9SnU/DzSalasKvzOw7w9rFTuiVK0ynPiUer8wGBg1YZCKc/13CbK8Wl9NR4 APpxHegL+kVXM9Izotehcm37zLouaaRBagR8C2HJMO/vTseKbEeBf7i1NKLZJ3mKY2OK j/XL3X3lvFMNdH8QKKVDB4tSlqzm3I/W9EpMfQ5HOXTbPHK+4EojSm0OZFHpYXHU/2OH OlyjaRbmhk/EUzovDqoPxMNlU/y9ikNwPlQPTqEdbe+5LKIENXw7Mt1q6/MmoBZTV7xW 9lyA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784017775; x=1784622575; h=to:cc:date:message-id:subject:mime-version :content-transfer-encoding:content-type:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=O5qcr43MYyk8Rdnv8NoBGU4eaKU8JCviUqurIFf1yFI=; b=pwej/ExOMu+NppHM9OkK9BEJvYkxCyIGyMFT+mzMtvN4m3OJN6YbiA9a5NhkvTQRQs M/XgUIMICB6iWUbrY/ID5uiGWsiBSRzXV3ymk4y/ANUXGfYC6N9OEYAAyoxa32nREQNj YELMwdV8ns5sAuHf6qIdPWs9wja++6uu2CV6SU5y5syInlcDVxvxoB//Lqd7c9T2yAEr M3DXAAMHYcwGafEGC9r2YjpJivmXe2Sy5TxO2LkppXNWutKcjTWMckhxrs3gjEG3oGEO +vPigODpUkVWEmpC4XpBCEVI3JQkJbrzPs+wLdVRSbiQSynyHbeFAQhKaei7aQevOY01 +qmQ== X-Gm-Message-State: AOJu0YxvjYO7fAV6VsKPJ0dWr235J9RWVqkuIFUrn3ejPXAIqDtrEHiE PtC3HA7OstUlFsWB9SsmGGNnRofH5SW4gWOrPTujD+1rldi3FkDWQNzRqi9kh277TEw= X-Gm-Gg: AfdE7ckWoFDbrwVF7NmRc4DUH2FQ5ezKKT7NQfOtm80LFBh8UuhHiyreV4aSd6EMFME Re8aH/iLMq3OiMvWEZF4KsvPWb8Kr47IqjfMw15voY6sm72JgJhCAPQYB8ceHqTq7pdf1lLaCmh xuf8LYD/Kt1lVXT3ZdQ3D20lZbcL2WO3zokapGvS4QPrHpAkJiTFvFNvYpCLSdvo/i0kII/H9Y9 bjaGl5ezoE3Hn0Sph0zRlG6J8Pq6s18S05z5KAAkkATJZtQVG2cGErHAOsQtlqFbFg5ic6zrE9G sj63cCyIkMZ14kg8HRHX5E6jYGkSIATsE4cO/4k4HKTFa1Ovk3gIS7M9yDtSHgtRfcJTTTVxTVr VdHHW406vWGudpmDCJ1QLFAxscZMJIWokIJTnPMGVRi4huJS+/OgS6CaqdsJjz585Qqd89ESBKh aKvZVxSL95SGdQMy/+DgRI0bJbwkajl6GYFncqh/A4IKt1o4MSlIoDzroi4QjeJxDu0V3d0+VGY JdPiDpfZZiOES26gJqKORNP3LERElex5h7n6YEbfehgq46hjiFBI5aN7ijFMLLqkAFusWqO2Bq9 Ie8= X-Received: by 2002:a17:906:f20f:b0:c16:139f:b803 with SMTP id a640c23a62f3a-c161f3dd4demr412435366b.43.1784017775273; Tue, 14 Jul 2026 01:29:35 -0700 (PDT) Received: from smtpclient.apple (83.10.38.128.ipv4.supernova.orange.pl. [83.10.38.128]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c15f7137225sm628321466b.53.2026.07.14.01.29.34 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 14 Jul 2026 01:29:34 -0700 (PDT) From: Norbert Szetei Content-Transfer-Encoding: quoted-printable Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH] ALSA: seq: close a re-opened queue timer in the destructor Message-Id: <422FDB81-2A68-47C7-A22D-2D3301E2E86D@doyensec.com> Date: Tue, 14 Jul 2026 10:29:23 +0200 Cc: linux-kernel@vger.kernel.org, tiwai@suse.de, perex@perex.cz To: linux-sound@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" queue_delete() closes the queue timer, then frees it. snd_seq_timer_close() clears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and snd_seq_timer_delete() frees q->timer. A borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT that took a queueptr() use_lock reference before the queue was unlinked runs snd_seq_timer_open() after the close. Open refuses re-open only while timeri is set, and the close just cleared it, so it re-opens timeri. snd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop= () is a no-op, because running was cleared first. So it frees q->timer with the instance still live. The queue is freed next. The instance stays on the global timer with callback_data pointing at the freed queue. A non-owner START on the unlocked queue arms it. The next tick derefs the freed queue in snd_seq_timer_interrupt(). Reachable by an unprivileged user with access to /dev/snd/seq. No CAP and no queue ownership required. Close any lingering instance in the destructor. There, ->timeri can no longer change: the queue is unlinked and all use_lock borrowers have drained, so no snd_seq_queue_use() can re-open it. Close it before clearing q->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt= () to finish, and that callback still reads q->timer (via snd_seq_check_queue(= )), so q->timer must stay valid until it drains. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Norbert Szetei --- sound/core/seq/seq_timer.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/sound/core/seq/seq_timer.c b/sound/core/seq/seq_timer.c index 4cd7211ccf48..419288eec4bb 100644 --- a/sound/core/seq/seq_timer.c +++ b/sound/core/seq/seq_timer.c @@ -61,12 +61,23 @@ struct snd_seq_timer *snd_seq_timer_new(void) void snd_seq_timer_delete(struct snd_seq_timer **tmr) { struct snd_seq_timer *t =3D *tmr; - *tmr =3D NULL; + struct snd_timer_instance *ti; =20 if (t =3D=3D NULL) { pr_debug("ALSA: seq: snd_seq_timer_delete() called with NULL timer\n"); return; } + + scoped_guard(spinlock_irq, &t->lock) { + ti =3D t->timeri; + t->timeri =3D NULL; + } + if (ti) { + snd_timer_close(ti); + snd_timer_instance_free(ti); + } + + *tmr =3D NULL; t->running =3D 0; =20 /* reset time */ --=20 2.55.0