From: GitHub pull_request - reopened <github@alsa-project.org>
To: alsa-devel@alsa-project.org
Subject: alsa-lib: security hardening — UCM, conf parser, topology, PCM plugins (6 findings)
Date: Wed, 30 Sep 2026 20:59:38 +0200 (CEST) [thread overview]
Message-ID: <18da2e5c767cd000-webhooks-bot@alsa-project.org> (raw)
In-Reply-To: <alsa-project/alsa-lib/pr/527@alsa-project.org>
alsa-project/alsa-lib pull request #527 was reopened from HarshRajSinghania:
This PR addresses **six independently-triggered security hardening issues** found during a source audit of commit `f84cd4c`, all verified with proof-of-concept programs.
A3 (`shell`/`system()`) and A6 (PCM file `popen`) are intentional features and are not patched here — hardening suggestions noted inline for maintainer consideration.
---
### A1 — UCM `sysw` path traversal (CWE-22) · `src/ucm/main.c`
`execute_sysw()` concatenates the sysfs root with a caller-supplied string via `snprintf()` with no `..` rejection or `realpath()` confinement. A UCM path like `../../etc/cron.d/x:value` writes to an arbitrary filesystem location. **Fix:** `realpath()` confinement — reject if resolved path does not remain within the sysfs root.
### A2 — UCM `cfg-save` unrestricted path (CWE-73) · `src/ucm/main.c`
`execute_cfgsave()` calls `snd_output_stdio_open(&out, file, "w+")` with a raw caller-supplied `file` and no restriction. Any writable path (e.g. `~/.ssh/authorized_keys`) is reachable. **Fix:** `realpath()` check — confine to `XDG_RUNTIME_DIR` (fallback `/tmp`).
### A4 — Config parser absolute include traversal (CWE-22) · `src/conf.c`
`input_stdio_open()` immediately opens any absolute path (`file[0]=='/'`) without checking for `..` components. A planted config with `</../../etc/shadow>` can read arbitrary files. **Fix:** reject paths containing `/../`.
### A5 — Topology control `uint32_t` integer overflow (CWE-190) · `src/topology/ctl.c`
`size2 = x->size + x->priv.size` is computed in 32-bit unsigned arithmetic before being widened to `size_t`. On a 64-bit host, `0xFFFFFFF0 + 0x20 = 0x10` (wraps), bypassing the subsequent `size2 > size` guard. Three sites: `tplg_decode_control_mixer`, `tplg_decode_control_enum`, `tplg_decode_control_bytes` (distinct from CVE-2026-25068 which was `tplg_decode_control_mixer1`). **Fix:** pre-check for overflow, then `(size_t)x->size + (size_t)x->priv.size`.
### A7 — PCM `route` plugin unbounded `ttable` allocation (CWE-770) · `src/pcm/pcm_route.c`
`csize`/`ssize` grow from config-supplied channel indices with no upper bound before `malloc(csize * ssize * sizeof(entry))`. Index `1073741823` → `malloc(8 GB)`. **Fix:** cap both at 1024 (consistent with `dmix`, `softvol`, other PCM plugins).
### A8 — PCM `multi` sparse bindings OOB assert (CWE-617) · `src/pcm/pcm_multi.c`
Sparse binding maps leave `sidxs[i] == -1` for gap indices. `assert(schannels[i] < schannels_count[sidxs[i]])` then dereferences `schannels_count[-1]` → SIGABRT (debug) / OOB read (NDEBUG). **Fix:** replace both `assert()`s with explicit `-EINVAL` returns with bounds and sign checks.
---
**Verified:** all six PoC programs confirmed on `libasound2 1.2.14` / `gcc 14.2`, commit `f84cd4c`.
**Signed-off-by:** Harsh Raj Singhania <raj.harshraut@gmail.com>
Request URL : https://github.com/alsa-project/alsa-lib/pull/527
Patch URL : https://github.com/alsa-project/alsa-lib/pull/527.patch
Repository URL: https://github.com/alsa-project/alsa-lib
prev parent reply other threads:[~2026-09-30 19:00 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <alsa-project/alsa-lib/pr/527@alsa-project.org>
2026-09-19 5:11 ` alsa-lib: security hardening — UCM, conf parser, topology, PCM plugins (6 findings) GitHub pull_request - opened
2026-09-30 18:59 ` GitHub pull_request - reopened [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=18da2e5c767cd000-webhooks-bot@alsa-project.org \
--to=github@alsa-project.org \
--cc=alsa-devel@alsa-project.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox