From: Takashi Iwai <tiwai@suse.de>
To: Baul Lee <baul.lee@xbow.com>
Cc: linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org,
tiwai@suse.com, tiwai@suse.de, perex@perex.cz,
clemens@ladisch.de, federico.kirschbaum@xbow.com,
stable@vger.kernel.org
Subject: Re: [PATCH v2] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
Date: Sun, 26 Jul 2026 09:49:47 +0200 [thread overview]
Message-ID: <8733x6b36s.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260726074500.50145-1-baul.lee@xbow.com>
On Sun, 26 Jul 2026 09:45:00 +0200,
Baul Lee wrote:
>
> snd_usbmidi_akai_output() computes its fill-loop bound
>
> buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
>
> as a signed int, so a small device-advertised bulk-OUT max_transfer
> makes buf_end negative. The loop guard then compares the u32
> urb->transfer_buffer_length against that negative int: the usual
> arithmetic conversion turns buf_end into a large unsigned value, so the
> guard stays true and each iteration keeps appending SysEx framing and
> payload bytes past the end of the URB transfer buffer, which is only
> max_transfer bytes long.
>
> A USB device that advertises a tiny bulk-OUT endpoint can therefore
> trigger an attacker-length- and content-controlled heap out-of-bounds
> write when a process writes to the created /dev/snd/midiC*D* node.
>
> Return early when there is no room for even one SysEx, so the loop is
> never entered with a bound that would wrap. The loop is the last
> statement of the function, so bailing out is equivalent to it not
> running.
>
> Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
>
> Fixes: 4434ade8c933 ("ALSA: usb-audio: add support for Akai MPD16")
> Suggested-by: Takashi Iwai <tiwai@suse.de>
> Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
> Reported-by: Baul Lee <baul.lee@xbow.com>
> Cc: stable@vger.kernel.org
> Signed-off-by: Baul Lee <baul.lee@xbow.com>
> ---
> v2: use an explicit "buf_end <= 0" early return instead of casting the
> loop guard to int, as suggested by Takashi Iwai. Verified with the
> reproducer under KASAN on v7.2-rc4: without the patch the kernel
> reports a slab-out-of-bounds write in snd_usbmidi_akai_output(),
> with it the same run is clean.
Applied now. Thanks!
Takashi
prev parent reply other threads:[~2026-07-26 7:49 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-26 5:20 [PATCH] ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() Baul Lee
2026-07-26 7:05 ` Takashi Iwai
2026-07-26 7:45 ` [PATCH v2] " Baul Lee
2026-07-26 7:49 ` Takashi Iwai [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8733x6b36s.wl-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=baul.lee@xbow.com \
--cc=clemens@ladisch.de \
--cc=federico.kirschbaum@xbow.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=stable@vger.kernel.org \
--cc=tiwai@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.