From: Takashi Iwai <tiwai@suse.de>
To: Xiang Mei <xmei5@asu.edu>
Cc: clemens@ladisch.de, linux-sound@vger.kernel.org, tiwai@suse.com,
perex@perex.cz, co+24304d323d28f156@bugs.sh,
stable@vger.kernel.org
Subject: Re: [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes
Date: Mon, 28 Sep 2026 13:10:57 +0200 [thread overview]
Message-ID: <878q4l7hry.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260918225753.1278505-1-xmei5@asu.edu>
On Sat, 19 Sep 2026 00:57:53 +0200,
Xiang Mei wrote:
>
> detect_usb_format() cross-checks bSubframeSize, bBitResolution and
> tSamFreq between the capture and playback interfaces, but never relates
> the two endpoints' wMaxPacketSize and bNrChannels. Each playback URB
> gets a buffer of ua->playback.max_packet_bytes, while the number of
> bytes written into it is derived from the capture stream:
> capture_urb_complete() computes frames from the received capture packet
> and capture.frame_bytes, and start_usb_playback() and playback_work()
> multiply that by playback.frame_bytes.
>
> A device declaring a large capture wMaxPacketSize with few capture
> channels and a small playback wMaxPacketSize with many playback channels
> therefore memset()s and memcpy()s past the end of the playback buffer,
> in open() of the PCM node the driver registers during probe.
> usb_submit_urb() rejects the over-long iso_frame_desc[0].length with
> -EMSGSIZE, but only after the write.
>
> Reject such descriptors at probe time. Genuine UA-101/UA-1000 hardware
> declares proportional packet sizes and is unaffected.
>
> BUG: KASAN: slab-out-of-bounds in start_usb_playback (sound/usb/misc/ua101.c:586)
> Write of size 2048 at addr ffff8881098f3c00 by task exploit/5021
> Call Trace:
> __asan_memset (mm/kasan/shadow.c:84)
> start_usb_playback (sound/usb/misc/ua101.c:586)
> playback_pcm_open (sound/usb/misc/ua101.c:679)
> snd_pcm_open_substream (sound/core/pcm_native.c:2829)
> snd_pcm_open (sound/core/pcm_native.c:2865 sound/core/pcm_native.c:2932)
> snd_pcm_playback_open (sound/core/pcm_native.c:2891)
> snd_open (sound/core/sound.c:166)
> chrdev_open (fs/char_dev.c:411)
> do_dentry_open (fs/open.c:996)
> vfs_open (fs/open.c:1101)
> path_openat (fs/namei.c:4837 fs/namei.c:5000)
> do_file_open (fs/namei.c:5029)
> do_sys_openat2 (fs/open.c:1417)
> __x64_sys_openat (fs/open.c:1423 fs/open.c:1439 fs/open.c:1434)
> do_syscall_64 (arch/x86/entry/syscall_64.c:61 arch/x86/entry/syscall_64.c:84)
> entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
>
> The buggy address belongs to the object at ffff8881098f3c00
> which belongs to the cache kmalloc-192 of size 192
> The buggy address is located 0 bytes inside of
> allocated 168-byte region [ffff8881098f3c00, ffff8881098f3ca8)
>
> Cc: stable@vger.kernel.org
> Fixes: 63978ab3e3e9 ("sound: add Edirol UA-101 support")
> Reported-by: <co+24304d323d28f156@bugs.sh>
> Assisted-by: LLM
> Signed-off-by: Xiang Mei <xmei5@asu.edu>
Applied now. Thanks.
Takashi
prev parent reply other threads:[~2026-09-28 11:11 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 22:57 [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes Xiang Mei
2026-09-28 11:10 ` Takashi Iwai [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=878q4l7hry.wl-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=clemens@ladisch.de \
--cc=co+24304d323d28f156@bugs.sh \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=stable@vger.kernel.org \
--cc=tiwai@suse.com \
--cc=xmei5@asu.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox