From: Takashi Iwai <tiwai@suse.de>
To: Tristan Madani <tristmd@gmail.com>
Cc: Jaroslav Kysela <perex@perex.cz>, Takashi Iwai <tiwai@suse.com>,
linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org,
Tristan Madani <tristan@talencesecurity.com>,
stable@vger.kernel.org
Subject: Re: [PATCH 1/2] ALSA: usbusx2y: fix in04_last array size causing slab OOB read
Date: Fri, 04 Sep 2026 12:25:46 +0200 [thread overview]
Message-ID: <87wlt15n4l.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260904095154.3905899-1-tristmd@gmail.com>
On Fri, 04 Sep 2026 11:51:54 +0200,
Tristan Madani wrote:
>
> From: Tristan Madani <tristan@talencesecurity.com>
>
> The in04_last array in struct usx2ydev is declared as char[24], but
> in04_buf (the source for memcpy) is allocated with kmalloc(21). In
> i_usx2y_in04_int(), when ctl_snapshot_last == -2 (initialization path):
>
> memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));
>
> This copies 24 bytes from a 21-byte slab allocation, reading 3 bytes
> past the end of the kmalloc-32 object.
>
> The comparison loop already uses the correct bound of 21:
>
> for (i = 0; i < 21; i++) {
>
> Fix by reducing the in04_last array to 21 bytes, matching the actual
> USB interrupt transfer size and the in04_buf allocation.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@vger.kernel.org
> Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Better to introduce a constant definition and use it in all places
instead of magic numbers. Could you rework your patches with it?
thanks,
Takashi
prev parent reply other threads:[~2026-09-04 10:26 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 9:51 [PATCH 1/2] ALSA: usbusx2y: fix in04_last array size causing slab OOB read Tristan Madani
2026-09-04 9:52 ` [PATCH 2/2] ALSA: usbusx2y: validate URB actual_length in interrupt callback Tristan Madani
2026-09-04 10:25 ` Takashi Iwai [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87wlt15n4l.wl-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=stable@vger.kernel.org \
--cc=tiwai@suse.com \
--cc=tristan@talencesecurity.com \
--cc=tristmd@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.