All of lore.kernel.org
 help / color / mirror / Atom feed
From: Takashi Iwai <tiwai@suse.de>
To: Edward Adam Davis <eadavis@qq.com>
Cc: syzbot+6db0415d6d5c635f72cb@syzkaller.appspotmail.com,
	linux-kernel@vger.kernel.org, linux-sound@vger.kernel.org,
	linux-usb@vger.kernel.org, perex@perex.cz,
	syzkaller-bugs@googlegroups.com, tiwai@suse.com
Subject: Re: [PATCH] ALSA: usb-audio: Prevent excessive number of frames
Date: Tue, 13 Jan 2026 15:06:11 +0100	[thread overview]
Message-ID: <87ldi1ppyk.wl-tiwai@suse.de> (raw)
In-Reply-To: <tencent_9AECE6CD2C7A826D902D696C289724E8120A@qq.com>

On Tue, 13 Jan 2026 09:29:23 +0100,
Edward Adam Davis wrote:
> 
> In this case, the user constructed the parameters with maxpacksize 40
> for rate 22050 / pps 1000, and packsize[0] 22 packsize[1] 23. The buffer
> size for each data URB is maxpacksize * packets, which in this example
> is 40 * 6 = 240; When the user performs a write operation to send audio
> data into the ALSA PCM playback stream, the calculated number of frames
> is packsize[0] * packets = 264, which exceeds the allocated URB buffer
> size, triggering the out-of-bounds (OOB) issue reported by syzbot [1].
> 
> Added a check for the number of single data URB frames when calculating
> the number of frames to prevent [1].
> 
> [1]
> BUG: KASAN: slab-out-of-bounds in copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487
> Write of size 264 at addr ffff88804337e800 by task syz.0.17/5506
> Call Trace:
>  copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487
>  prepare_playback_urb+0x953/0x13d0 sound/usb/pcm.c:1611
>  prepare_outbound_urb+0x377/0xc50 sound/usb/endpoint.c:333
> 
> Reported-by: syzbot+6db0415d6d5c635f72cb@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=6db0415d6d5c635f72cb
> Tested-by: syzbot+6db0415d6d5c635f72cb@syzkaller.appspotmail.com
> Signed-off-by: Edward Adam Davis <eadavis@qq.com>

Applied now.  Thanks.


Takashi

      reply	other threads:[~2026-01-13 14:06 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-01-13  1:31 [syzbot] [sound?] [usb?] KASAN: slab-out-of-bounds Write in copy_to_urb (2) syzbot
2026-01-13  7:54 ` Edward Adam Davis
2026-01-13  8:15   ` syzbot
2026-01-13  8:29 ` [PATCH] ALSA: usb-audio: Prevent excessive number of frames Edward Adam Davis
2026-01-13 14:06   ` Takashi Iwai [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87ldi1ppyk.wl-tiwai@suse.de \
    --to=tiwai@suse.de \
    --cc=eadavis@qq.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=syzbot+6db0415d6d5c635f72cb@syzkaller.appspotmail.com \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=tiwai@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.