From: Takashi Iwai <tiwai@suse.de>
To: Baul Lee <baul.lee@xbow.com>
Cc: g@b4.vu, perex@perex.cz, tiwai@suse.com,
linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org,
federico.kirschbaum@xbow.com, stable@vger.kernel.org
Subject: Re: [PATCH] ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
Date: Tue, 04 Aug 2026 18:06:07 +0200 [thread overview]
Message-ID: <875x1pj2fk.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260804123611.91715-1-baul.lee@xbow.com>
On Tue, 04 Aug 2026 14:36:11 +0200,
Baul Lee wrote:
>
> fcp_ioctl_set_meter_map() bounds the user-supplied Level Meter map size
> by the driver's own limit of 255
>
> if (map.map_size < 1 || map.map_size > 255 ||
> map.meter_slots < 1 || map.meter_slots > 255)
> return -EINVAL;
>
> and passes it to fcp_add_new_ctl() as the control's channel count, where
> it is stored as elem->channels.
>
> Every control read writes into struct snd_ctl_elem_value, whose integer
> array is declared long value[128], so the limit is 128, not 255.
> fcp_meter_ctl_get() stores one 64-bit word per channel into that array
> with no bound of its own:
>
> for (i = 0; i < elem->channels; i++) {
> int idx = private->meter_level_map[i];
> int value = idx < 0 ? 0 : le32_to_cpu(resp[idx]);
>
> ucontrol->value.integer.value[i] = value;
> }
>
> snd_ctl_elem_read_user() serves that object from
> memdup_user(_control, sizeof(*control)), 1224 bytes on LP64 out of
> kmalloc-2048. offsetof(struct snd_ctl_elem_value, value) is 72, so
> element i is written at byte 72 + 8 * i and element 144 already lands
> past the allocation. At map_size 255 the last store ends at byte 2112,
> 888 bytes past the object and 64 bytes into the adjacent slab object.
> The stored words come from the device and meter_level_map[] selects
> which word lands in which slot, so extent and contents are both
> controlled.
>
> The core does not catch this. snd_ctl_check_elem_info() is reached only
> from __snd_ctl_elem_info(), which snd_ctl_elem_read() calls under
> CONFIG_SND_CTL_DEBUG; without that option snd_ctl_skip_validation() is a
> compile-time true. __snd_ctl_add_replace() validates kcontrol->count and
> never inspects elem->channels.
>
> Installing an oversized map needs CAP_SYS_RAWIO, but the control outlives
> the hwdep descriptor that created it, so the out-of-bounds stores are
> issued by any process able to read controls on /dev/snd/controlC0.
>
> KASAN on 7.2.0-rc5 (arm64), triggered by an unprivileged control read:
>
> BUG: KASAN: slab-out-of-bounds in fcp_meter_ctl_get
> Write of size 8 at addr ffff000017af04c8 by task fcp_trigger/185
> __asan_store8
> fcp_meter_ctl_get
> snd_ctl_elem_read
> snd_ctl_ioctl
> Allocated by task 185:
> memdup_user
> snd_ctl_ioctl
> The buggy address is located 0 bytes to the right of
> allocated 1224-byte region [ffff000017af0000, ffff000017af04c8)
>
> Bound the map size by the ABI limit rather than by 255, and bound the
> store loop at the sink so it cannot run past the value array whatever
> elem->channels holds.
>
> Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
>
> Fixes: 46757a3e7d50 ("ALSA: FCP: Add Focusrite Control Protocol driver")
> Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
> Reported-by: Baul Lee <baul.lee@xbow.com>
> Cc: stable@vger.kernel.org
> Signed-off-by: Baul Lee <baul.lee@xbow.com>
Applied now. Thanks.
Takashi
prev parent reply other threads:[~2026-08-04 16:06 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 12:36 [PATCH] ALSA: FCP: fix OOB write in fcp_meter_ctl_get() Baul Lee
2026-08-04 16:06 ` Takashi Iwai [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=875x1pj2fk.wl-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=baul.lee@xbow.com \
--cc=federico.kirschbaum@xbow.com \
--cc=g@b4.vu \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=stable@vger.kernel.org \
--cc=tiwai@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.