Skip to content

Commit 980fabf

Browse files
tmlemankv2019i
authored andcommitted
audio: module_adapter: clear pipeline back-pointers on create failure
A module's init op can store its comp_dev into the parent pipeline's source_comp/sink_comp before module creation completes. When a later step of module_adapter_new_ext fails, the dev is freed on the err: path before it has been added to the IPC component list, so ipc_comp_free back-pointer cleanup never runs for it and pipeline->source_comp/sink_comp is left pointing at freed memory. A subsequent SET_PIPELINE_STATE then dereferences the freed component in ipc4 pipeline_get_host_dev. Found by the IPC4 libFuzzer target under AddressSanitizer. Clear pipeline->source_comp/sink_comp/sched_comp that reference the dev being freed on the creation-failure path, mirroring the cleanup ipc_comp_free already performs for registered components. Signed-off-by: Tomasz Leman <tomasz.m.leman@intel.com>
1 parent cd3a114 commit 980fabf

1 file changed

Lines changed: 15 additions & 0 deletions

File tree

‎src/audio/module_adapter/module_adapter.c‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -362,6 +362,21 @@ struct comp_dev *module_adapter_new_ext(const struct comp_driver *drv,
362362
if (dev->task)
363363
schedule_task_free(dev->task);
364364
#endif
365+
/* When module_init is called in this function, it can store this dev in its pipeline.
366+
* This happens in the case of the copier (copier_dai_init and copier_host_create).
367+
* The pointers remain set even after a failure. The dev is freed below on this
368+
* creation-failure path before it was added to the IPC component list, so ipc_comp_free()'s
369+
* back-pointer cleanup will never run for it. Clear the stale references now to prevent
370+
* a later use-after-free when the pipeline is prepared or triggered.
371+
*/
372+
if (dev->pipeline) {
373+
if (dev->pipeline->source_comp == dev)
374+
dev->pipeline->source_comp = NULL;
375+
if (dev->pipeline->sink_comp == dev)
376+
dev->pipeline->sink_comp = NULL;
377+
if (dev->pipeline->sched_comp == dev)
378+
dev->pipeline->sched_comp = NULL;
379+
}
365380
module_adapter_mem_free(mod);
366381
return NULL;
367382
}

0 commit comments

Comments
 (0)