All of lore.kernel.org
 help / color / mirror / Atom feed
From: Baul Lee <baul.lee@xbow.com>
To: linux-sound@vger.kernel.org
Cc: tiwai@suse.com, clemens@ladisch.de, perex@perex.cz,
	federico.kirschbaum@xbow.com, Baul Lee <baul.lee@xbow.com>,
	stable@vger.kernel.org
Subject: [PATCH] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
Date: Sun, 26 Jul 2026 14:20:40 +0900	[thread overview]
Message-ID: <20260726052040.41315-1-baul.lee@xbow.com> (raw)

snd_usbmidi_akai_output() computes its fill-loop bound

	buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;

as a signed int, so a small device-advertised bulk-OUT max_transfer
makes buf_end negative.  The loop guard then compares the u32
urb->transfer_buffer_length against that negative int: the usual
arithmetic conversion turns buf_end into a large unsigned value, so the
guard stays true and each iteration keeps appending SysEx framing and
payload bytes past the end of the URB transfer buffer, which is only
max_transfer bytes long.

A USB device that advertises a tiny bulk-OUT endpoint can therefore
trigger an attacker-length- and content-controlled heap out-of-bounds
write when a process writes to the created /dev/snd/midiC*D* node.

Perform the comparison in signed arithmetic so that a negative buf_end
stops the loop instead of wrapping to a huge unsigned bound.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

Fixes: 4434ade8c933 ("ALSA: usb-audio: add support for Akai MPD16")
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
---
 sound/usb/midi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/usb/midi.c b/sound/usb/midi.c
index d87e3f357cf7..cc7df77632a1 100644
--- a/sound/usb/midi.c
+++ b/sound/usb/midi.c
@@ -799,7 +799,7 @@ static void snd_usbmidi_akai_output(struct snd_usb_midi_out_endpoint *ep,
 	buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
 
 	/* only try adding more data when there's space for at least 1 SysEx */
-	while (urb->transfer_buffer_length < buf_end) {
+	while ((int)urb->transfer_buffer_length < buf_end) {
 		count = snd_rawmidi_transmit_peek(substream,
 						  tmp, MAX_AKAI_SYSEX_LEN);
 		if (!count) {
-- 
2.50.1 (Apple Git-155)


             reply	other threads:[~2026-07-26  5:20 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-26  5:20 Baul Lee [this message]
2026-07-26  7:05 ` [PATCH] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() Takashi Iwai
2026-07-26  7:45 ` [PATCH v2] " Baul Lee
2026-07-26  7:49   ` Takashi Iwai

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260726052040.41315-1-baul.lee@xbow.com \
    --to=baul.lee@xbow.com \
    --cc=clemens@ladisch.de \
    --cc=federico.kirschbaum@xbow.com \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=stable@vger.kernel.org \
    --cc=tiwai@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.