From: Takashi Iwai <tiwai@suse.de>
To: Baul Lee <baul.lee@xbow.com>
Cc: linux-sound@vger.kernel.org, tiwai@suse.com, clemens@ladisch.de,
perex@perex.cz,
Federico Kirschbaum <federico.kirschbaum@xbow.com>
Subject: Re: [PATCH] ALSA: usb-audio: fix out-of-bounds write in snd_usbmidi_akai_output()
Date: Sat, 25 Jul 2026 16:45:56 +0200 [thread overview]
Message-ID: <87pl0bb00r.wl-tiwai@suse.de> (raw)
In-Reply-To: <CAEM_DMFgNNvwP7iXA-OVo7A7g_wuQEfTFOi35tzdP1RP6kpPuA@mail.gmail.com>
On Sat, 25 Jul 2026 11:40:13 +0200,
Baul Lee wrote:
>
>
> snd_usbmidi_akai_output() computes its fill-loop bound
>
> buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
>
> as a signed int, so a small device-advertised bulk-OUT max_transfer makes
> buf_end negative. The loop guard then compares the u32
> urb->transfer_buffer_length against that negative int: the usual arithmetic
> conversion turns buf_end into a large unsigned value, so the guard stays
> true and each iteration keeps appending SysEx framing and payload bytes
> past the end of the URB transfer buffer, which is only max_transfer bytes
> long.
>
> A USB device that advertises a tiny bulk-OUT endpoint can therefore trigger
> an attacker-length- and content-controlled heap out-of-bounds write when a
> process writes to the created /dev/snd/midiC*D* node.
>
> Perform the comparison in signed arithmetic so that a negative buf_end
> stops the loop instead of wrapping to a huge unsigned bound.
>
> Fixes: 4434ade8c933 ("ALSA: usb-audio: add support for Akai MPD16")
> Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
> Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
> Reported-by: Baul Lee <baul.lee@xbow.com>
First of all, please put your Signed-off-by tag. It's a legal
requirement for upstreaming.
About the patch:
> ---
> sound/usb/midi.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/sound/usb/midi.c b/sound/usb/midi.c
> index d87e3f357cf7..cc7df77632a1 100644
> --- a/sound/usb/midi.c
> +++ b/sound/usb/midi.c
> @@ -799,7 +799,7 @@ static void snd_usbmidi_akai_output(struct
> snd_usb_midi_out_endpoint *ep,
> buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
>
> /* only try adding more data when there's space for at least 1 SysEx */
> - while (urb->transfer_buffer_length < buf_end) {
> + while ((int)urb->transfer_buffer_length < buf_end) {
> count = snd_rawmidi_transmit_peek(substream,
> tmp, MAX_AKAI_SYSEX_LEN);
> if (!count) {
> --
The spaces are malformed due to your mailer, hence the patch can't be
applied cleanly via git-am. Please check your mailer setup.
At best, test once submitting to yourself and check whether you can
apply the patch cleanly via git-am locally beforehand.
BTW, your patches don't seem reached to linux-sound ML by some reason;
I couldn't find your posts in lore.kernel.org. I'm not sure what went
wrong.
All points above applied to your two other patches, too.
thanks,
Takashi
parent reply other threads:[~2026-07-25 14:46 UTC|newest]
Thread overview: expand[flat|nested] mbox.gz Atom feed
[parent not found: <CAEM_DMFgNNvwP7iXA-OVo7A7g_wuQEfTFOi35tzdP1RP6kpPuA@mail.gmail.com>]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87pl0bb00r.wl-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=baul.lee@xbow.com \
--cc=clemens@ladisch.de \
--cc=federico.kirschbaum@xbow.com \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=tiwai@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.