* [PATCH] ALSA: hda/hdmi: clamp sad_count in ELD proc write handler
@ 2026-10-08 8:51 Peter Ujfalusi
2026-10-08 10:11 ` Takashi Iwai
0 siblings, 1 reply; 2+ messages in thread
From: Peter Ujfalusi @ 2026-10-08 8:51 UTC (permalink / raw)
To: perex, tiwai; +Cc: linux-sound, stable
snd_hdmi_write_eld_info() parses a "sad_count N" line from the
root-writable ELD proc interface and assigns N directly to
e->sad_count with no upper bound, unlike the per-index "sadN_*" lines
a few lines below which are already bounded to ELD_MAX_SAD.
snd_hdmi_eld_update_pcm_info() later iterates
"for (i = 0; i < e->sad_count; i++)" over the fixed
e->sad[ELD_MAX_SAD] array, so an oversized sad_count read from the
proc file causes it to walk past the array.
Reject sad_count values above ELD_MAX_SAD, matching the existing
per-index guard.
Fixes: acb059938810 ("ALSA: hda - ELD proc interface write updates")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
---
sound/hda/codecs/hdmi/eld.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/sound/hda/codecs/hdmi/eld.c b/sound/hda/codecs/hdmi/eld.c
index 1464fd1c675b..fc6fe1b0873c 100644
--- a/sound/hda/codecs/hdmi/eld.c
+++ b/sound/hda/codecs/hdmi/eld.c
@@ -155,9 +155,11 @@ void snd_hdmi_write_eld_info(struct hdmi_eld *eld,
e->aud_synch_delay = val;
else if (!strcmp(name, "speakers"))
e->spk_alloc = val;
- else if (!strcmp(name, "sad_count"))
+ else if (!strcmp(name, "sad_count")) {
+ if (val > ELD_MAX_SAD)
+ continue;
e->sad_count = val;
- else if (!strncmp(name, "sad", 3)) {
+ } else if (!strncmp(name, "sad", 3)) {
sname = name + 4;
n = name[3] - '0';
if (name[4] >= '0' && name[4] <= '9') {
--
2.56.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] ALSA: hda/hdmi: clamp sad_count in ELD proc write handler
2026-10-08 8:51 [PATCH] ALSA: hda/hdmi: clamp sad_count in ELD proc write handler Peter Ujfalusi
@ 2026-10-08 10:11 ` Takashi Iwai
0 siblings, 0 replies; 2+ messages in thread
From: Takashi Iwai @ 2026-10-08 10:11 UTC (permalink / raw)
To: Peter Ujfalusi; +Cc: perex, tiwai, linux-sound, stable
On Thu, 08 Oct 2026 10:51:33 +0200,
Peter Ujfalusi wrote:
>
> snd_hdmi_write_eld_info() parses a "sad_count N" line from the
> root-writable ELD proc interface and assigns N directly to
> e->sad_count with no upper bound, unlike the per-index "sadN_*" lines
> a few lines below which are already bounded to ELD_MAX_SAD.
>
> snd_hdmi_eld_update_pcm_info() later iterates
> "for (i = 0; i < e->sad_count; i++)" over the fixed
> e->sad[ELD_MAX_SAD] array, so an oversized sad_count read from the
> proc file causes it to walk past the array.
>
> Reject sad_count values above ELD_MAX_SAD, matching the existing
> per-index guard.
>
> Fixes: acb059938810 ("ALSA: hda - ELD proc interface write updates")
> Cc: stable@vger.kernel.org
> Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Applied to for-next branch. Thanks.
Takashi
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-08 10:11 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-08 8:51 [PATCH] ALSA: hda/hdmi: clamp sad_count in ELD proc write handler Peter Ujfalusi
2026-10-08 10:11 ` Takashi Iwai
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox