* [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870
@ 2026-10-08 19:01 Artem Dinaburg
2026-10-08 19:01 ` [PATCH 6.6.y 1/2] ASoC: SOF: topology: Parse DAI type token for dspless mode Artem Dinaburg
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Artem Dinaburg @ 2026-10-08 19:01 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin,
Ranjani Sridharan, Péter Ujfalusi, Bard Liao, Mark Brown,
Pierre-Louis Bossart, Liam Girdwood, Daniel Baluta, Kai Vehmanen,
Jaroslav Kysela, Takashi Iwai, sound-open-firmware, alsa-devel,
linux-kernel, Pierre-Louis Bossart, Vijendar Mukunda, linux-sound,
Seppo Ingalsuo, Liam Girdwood
Hi Greg, Sasha, and maintainers,
I'm working through the smaller CVE backports still missing from 6.6.y.
These 2 upstream changes belong together for CVE-2025-21870. They must be
applied in this order because the later change depends on or completes the
earlier one.
The complete series is already present in 6.12.y, 6.18.y, and 7.2.y.
These fixes also affect 6.1.y, which will need a separate backport; this
series is only for 6.6.y.
Could you please consider this series for 6.6.y?
Thanks,
Artem Dinaburg
Series:
1. ASoC: SOF: topology: Parse DAI type token for dspless mode
2. ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers
base: v6.6.157 (79643295eba17affbd16ca97f3ef04c90266b28c) plus stable-queue
revision 958ddf240a33ef26b1771be944f0ea6c3b597472
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 6.6.y 1/2] ASoC: SOF: topology: Parse DAI type token for dspless mode
2026-10-08 19:01 [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870 Artem Dinaburg
@ 2026-10-08 19:01 ` Artem Dinaburg
2026-10-08 19:01 ` [PATCH 6.6.y 2/2] ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers Artem Dinaburg
2026-10-09 17:09 ` [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870 Sasha Levin
2 siblings, 0 replies; 4+ messages in thread
From: Artem Dinaburg @ 2026-10-08 19:01 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin,
Ranjani Sridharan, Péter Ujfalusi, Bard Liao, Mark Brown,
Pierre-Louis Bossart, Liam Girdwood, Daniel Baluta, Kai Vehmanen,
Jaroslav Kysela, Takashi Iwai, sound-open-firmware, alsa-devel,
linux-kernel, Pierre-Louis Bossart, Vijendar Mukunda, linux-sound
From: Ranjani Sridharan <ranjani.sridharan@linux.intel.com>
[ Upstream commit f9618ff105a0f6f5a6beed3edc557ea6a7d26df6 ]
Starting with LunarLake, the dspless mode can handle SoundWire/ALH,
DMIC and SSPs, so we need to identify the dai type from topology.
[ Backport to 6.6.y: 6.6.y still uses a stack-allocated snd_sof_dai in
the dspless topology path; parse the DAI type into that existing object
before connecting it. ]
Signed-off-by: Ranjani Sridharan <ranjani.sridharan@linux.intel.com>
Reviewed-by: Péter Ujfalusi <peter.ujfalusi@linux.intel.com>
Reviewed-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://msgid.link/r/20240213101247.28887-12-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
This is patch 1 of 2 in the ordered 6.6.y backport series.
This is the prerequisite needed for the CVE-2025-21870 backport. Stores and
populates each SOF DAI type so the following ALH hardening can distinguish
ALH DAI widgets from same-name non-DAI or non-ALH widgets.
This needed a target-specific adjustment; I called it out in the bracketed
backport note above.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
This fix also affects 6.1.y, which will need a separate backport; this
submission contains only the 6.6.y patch.
sound/soc/sof/ipc4-topology.c | 1 +
sound/soc/sof/sof-audio.h | 1 +
sound/soc/sof/topology.c | 11 +++++++++++
3 files changed, 13 insertions(+)
diff --git a/sound/soc/sof/ipc4-topology.c b/sound/soc/sof/ipc4-topology.c
index 39e4f0fdd5e4..18096aefce13 100644
--- a/sound/soc/sof/ipc4-topology.c
+++ b/sound/soc/sof/ipc4-topology.c
@@ -534,6 +534,7 @@ static int sof_ipc4_widget_setup_comp_dai(struct snd_sof_widget *swidget)
dev_dbg(scomp->dev, "dai %s node_type %u dai_type %u dai_index %d\n", swidget->widget->name,
node_type, ipc4_copier->dai_type, ipc4_copier->dai_index);
+ dai->type = ipc4_copier->dai_type;
ipc4_copier->data.gtw_cfg.node_id = SOF_IPC4_NODE_TYPE(node_type);
pipe_widget = swidget->spipe->pipe_widget;
diff --git a/sound/soc/sof/sof-audio.h b/sound/soc/sof/sof-audio.h
index 7620596ead07..13b9026ffd4d 100644
--- a/sound/soc/sof/sof-audio.h
+++ b/sound/soc/sof/sof-audio.h
@@ -514,6 +514,7 @@ struct snd_sof_route {
struct snd_sof_dai {
struct snd_soc_component *scomp;
const char *name;
+ u32 type;
int number_configs;
int current_config;
diff --git a/sound/soc/sof/topology.c b/sound/soc/sof/topology.c
index 7eb8eb35b137..011095722a80 100644
--- a/sound/soc/sof/topology.c
+++ b/sound/soc/sof/topology.c
@@ -2364,7 +2364,10 @@ static int sof_dspless_widget_ready(struct snd_soc_component *scomp, int index,
struct snd_soc_tplg_dapm_widget *tw)
{
if (WIDGET_IS_DAI(w->id)) {
+ static const struct sof_topology_token dai_tokens[] = {
+ {SOF_TKN_DAI_TYPE, SND_SOC_TPLG_TUPLE_TYPE_STRING, get_token_dai_type, 0}};
struct snd_sof_dev *sdev = snd_soc_component_get_drvdata(scomp);
+ struct snd_soc_tplg_private *priv = &tw->priv;
struct snd_sof_widget *swidget;
struct snd_sof_dai dai;
int ret;
@@ -2375,6 +2378,14 @@ static int sof_dspless_widget_ready(struct snd_soc_component *scomp, int index,
memset(&dai, 0, sizeof(dai));
+ ret = sof_parse_tokens(scomp, &dai.type, dai_tokens, ARRAY_SIZE(dai_tokens),
+ priv->array, le32_to_cpu(priv->size));
+ if (ret < 0) {
+ dev_err(scomp->dev, "Failed to parse DAI tokens for %s\n", tw->name);
+ kfree(swidget);
+ return ret;
+ }
+
ret = sof_connect_dai_widget(scomp, w, tw, &dai);
if (ret) {
kfree(swidget);
--
2.39.5
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH 6.6.y 2/2] ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers
2026-10-08 19:01 [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870 Artem Dinaburg
2026-10-08 19:01 ` [PATCH 6.6.y 1/2] ASoC: SOF: topology: Parse DAI type token for dspless mode Artem Dinaburg
@ 2026-10-08 19:01 ` Artem Dinaburg
2026-10-09 17:09 ` [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870 Sasha Levin
2 siblings, 0 replies; 4+ messages in thread
From: Artem Dinaburg @ 2026-10-08 19:01 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Peter Ujfalusi,
Seppo Ingalsuo, Liam Girdwood, Ranjani Sridharan, Bard Liao,
Mark Brown, Pierre-Louis Bossart, Liam Girdwood, Daniel Baluta,
Kai Vehmanen, Jaroslav Kysela, Takashi Iwai, sound-open-firmware,
alsa-devel, linux-kernel, Pierre-Louis Bossart, Vijendar Mukunda,
linux-sound
From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
[ Upstream commit 6fd60136d256b3b948333ebdb3835f41a95ab7ef ]
Other, non DAI copier widgets could have the same stream name (sname) as
the ALH copier and in that case the copier->data is NULL, no alh_data is
attached, which could lead to NULL pointer dereference.
We could check for this NULL pointer in sof_ipc4_prepare_copier_module()
and avoid the crash, but a similar loop in sof_ipc4_widget_setup_comp_dai()
will miscalculate the ALH device count, causing broken audio.
The correct fix is to harden the matching logic by making sure that the
1. widget is a DAI widget - so dai = w->private is valid
2. the dai (and thus the copier) is ALH copier
[ Backport to 6.6.y: Apply both widget-kind and ALH-type predicates to
the target loops; the newer node_type local is absent and unused by
this implementation. ]
Fixes: a150345aa758 ("ASoC: SOF: ipc4-topology: add SoundWire/ALH aggregation support")
Reported-by: Seppo Ingalsuo <seppo.ingalsuo@linux.intel.com>
Link: https://github.com/thesofproject/sof/pull/9652
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Reviewed-by: Liam Girdwood <liam.r.girdwood@intel.com>
Reviewed-by: Ranjani Sridharan <ranjani.sridharan@linux.intel.com>
Reviewed-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Link: https://patch.msgid.link/20250206084642.14988-1-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
This is patch 2 of 2 in the ordered 6.6.y backport series.
This change addresses CVE-2025-21870. Limits ALH aggregation searches to
DAI widgets of ALH type, preventing NULL private-data dereferences and
incorrect device counts from same-name non-DAI widgets.
Each loop checks WIDGET_IS_DAI() before interpreting w->private as a
DAI, then checks SOF_DAI_INTEL_ALH before incrementing the device
count or accessing copier data.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
This fix also affects 6.1.y, which will need a separate backport; this
submission contains only the 6.6.y patch.
sound/soc/sof/ipc4-topology.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/sound/soc/sof/ipc4-topology.c b/sound/soc/sof/ipc4-topology.c
index 18096aefce13..8911c075251c 100644
--- a/sound/soc/sof/ipc4-topology.c
+++ b/sound/soc/sof/ipc4-topology.c
@@ -577,10 +577,16 @@ static int sof_ipc4_widget_setup_comp_dai(struct snd_sof_widget *swidget)
}
list_for_each_entry(w, &sdev->widget_list, list) {
- if (w->widget->sname &&
+ struct snd_sof_dai *alh_dai;
+
+ if (!WIDGET_IS_DAI(w->id) || !w->widget->sname ||
strcmp(w->widget->sname, swidget->widget->sname))
continue;
+ alh_dai = w->private;
+ if (alh_dai->type != SOF_DAI_INTEL_ALH)
+ continue;
+
blob->alh_cfg.device_count++;
}
@@ -1692,11 +1698,13 @@ sof_ipc4_prepare_copier_module(struct snd_sof_widget *swidget,
*/
i = 0;
list_for_each_entry(w, &sdev->widget_list, list) {
- if (w->widget->sname &&
+ if (!WIDGET_IS_DAI(w->id) || !w->widget->sname ||
strcmp(w->widget->sname, swidget->widget->sname))
continue;
dai = w->private;
+ if (dai->type != SOF_DAI_INTEL_ALH)
+ continue;
alh_copier = (struct sof_ipc4_copier *)dai->private;
alh_data = &alh_copier->data;
blob->alh_cfg.mapping[i].device = alh_data->gtw_cfg.node_id;
--
2.39.5
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870
2026-10-08 19:01 [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870 Artem Dinaburg
2026-10-08 19:01 ` [PATCH 6.6.y 1/2] ASoC: SOF: topology: Parse DAI type token for dspless mode Artem Dinaburg
2026-10-08 19:01 ` [PATCH 6.6.y 2/2] ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers Artem Dinaburg
@ 2026-10-09 17:09 ` Sasha Levin
2 siblings, 0 replies; 4+ messages in thread
From: Sasha Levin @ 2026-10-09 17:09 UTC (permalink / raw)
To: stable
Cc: Sasha Levin, Artem Dinaburg, Greg Kroah-Hartman,
Ranjani Sridharan, Péter Ujfalusi, Bard Liao, Mark Brown,
Pierre-Louis Bossart, Liam Girdwood, Daniel Baluta, Kai Vehmanen,
Jaroslav Kysela, Takashi Iwai, sound-open-firmware, alsa-devel,
linux-kernel, Pierre-Louis Bossart, Vijendar Mukunda, linux-sound,
Seppo Ingalsuo, Liam Girdwood
> Could you please consider this series for 6.6.y?
Queued the series for 6.6, thanks.
--
Thanks,
Sasha
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-09 17:10 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-08 19:01 [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870 Artem Dinaburg
2026-10-08 19:01 ` [PATCH 6.6.y 1/2] ASoC: SOF: topology: Parse DAI type token for dspless mode Artem Dinaburg
2026-10-08 19:01 ` [PATCH 6.6.y 2/2] ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers Artem Dinaburg
2026-10-09 17:09 ` [PATCH 6.6.y 0/2] asoc: backport CVE-2025-21870 Sasha Levin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox