summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTakashi Iwai <tiwai@suse.de>2026-08-06 17:32:22 +0200
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-09-07 17:37:22 +0200
commitcf3af453a48c8d905512dfc44a5a59439b70f4f0 (patch)
treebaa21c3e05ff16e03bc64a9c00cf6ecc1bbb5ac3
parent8adda66edf795d4648f8e26f312e4414c535d25a (diff)
downloadlinux-cf3af453a48c8d905512dfc44a5a59439b70f4f0.tar.gz
linux-cf3af453a48c8d905512dfc44a5a59439b70f4f0.zip
ALSA: mts64: Check card index validity at probe
commit d18a260720f86a5f8b5fcfefc4ba2e9dd01c10f8 upstream. Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range. Cc: stable@vger.kernel.org Signed-off-by: Takashi Iwai <tiwai@suse.de> Link: https://patch.msgid.link/20260806153227.1460166-6-tiwai@suse.de Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r--sound/drivers/mts64.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/sound/drivers/mts64.c b/sound/drivers/mts64.c
index 36e9eab204ca..cefaa00b83e7 100644
--- a/sound/drivers/mts64.c
+++ b/sound/drivers/mts64.c
@@ -900,6 +900,12 @@ static int snd_mts64_probe(struct platform_device *pdev)
p = platform_get_drvdata(pdev);
platform_set_drvdata(pdev, NULL);
+ if (dev < 0) {
+ dev_warn(&pdev->dev,
+ "Invalid card index %d, using default 0\n", dev);
+ dev = 0;
+ }
+
if (dev >= SNDRV_CARDS)
return -ENODEV;
if (!enable[dev])