From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH 10/11] ALSA: line6: Fix potential OOB write in line6_capture_copy()
Date: Thu, 8 Oct 2026 21:25:50 +0200 [thread overview]
Message-ID: <20261008192553.300025-11-tiwai@suse.de> (raw)
In-Reply-To: <20261008192553.300025-1-tiwai@suse.de>
line6_capture_copy() copies the data for the original byte size, but
the buffer overwrap is checked against the frame size. Because of it,
when the data size isn't aligned in frames, the remaining bytes might
be still copied above the buffer size.
For avoiding the potential OOB write, correct the copied data size in
line6_capture_copy() to be aligned with frames.
Fixes: 1027f476f507 ("staging: line6: sync with upstream")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
sound/usb/line6/capture.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/sound/usb/line6/capture.c b/sound/usb/line6/capture.c
index 6dbaf30232f9..3e1f40d6b481 100644
--- a/sound/usb/line6/capture.c
+++ b/sound/usb/line6/capture.c
@@ -117,7 +117,8 @@ void line6_capture_copy(struct snd_line6_pcm *line6pcm, char *fbuf, int fsize)
} else {
/* copy single chunk */
memcpy(runtime->dma_area +
- line6pcm->in.pos_done * bytes_per_frame, fbuf, fsize);
+ line6pcm->in.pos_done * bytes_per_frame, fbuf,
+ frames * bytes_per_frame);
}
line6pcm->in.pos_done += frames;
--
2.55.0
next prev parent reply other threads:[~2026-10-08 19:26 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
2026-10-08 19:25 ` [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too Takashi Iwai
2026-10-08 19:25 ` [PATCH 02/11] ALSA: hda: Disable unsol event handling at error and shutdown paths Takashi Iwai
2026-10-08 19:25 ` [PATCH 03/11] ALSA: hda: Add lock around codec->registered flag manipulations Takashi Iwai
2026-10-09 10:13 ` kernel test robot
2026-10-09 10:56 ` kernel test robot
2026-10-08 19:25 ` [PATCH 04/11] ALSA: hda: Add NULL check for the driver pointer at unsol event work Takashi Iwai
2026-10-08 19:25 ` [PATCH 05/11] ALSA: caiaq: Register card at the final step Takashi Iwai
2026-10-08 19:25 ` [PATCH 06/11] ALSA: caiaq: Fix races at MIDI URB and trigger accesses Takashi Iwai
2026-10-08 19:25 ` [PATCH 07/11] ALSA: usb: us16x08: Fix racy accesses of mixer elements Takashi Iwai
2026-10-08 19:25 ` [PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments Takashi Iwai
2026-10-08 19:25 ` [PATCH 09/11] ALSA: line6: Reject too small max packet sizes Takashi Iwai
2026-10-08 19:25 ` Takashi Iwai [this message]
2026-10-08 19:25 ` [PATCH 11/11] ALSA: line6: Fix handling of zero-length capture packets Takashi Iwai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008192553.300025-11-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox