Linux Sound subsystem development
 help / color / mirror / Atom feed
From: Takashi Iwai <tiwai@suse.de>
To: Xiang Mei <xmei5@asu.edu>
Cc: clemens@ladisch.de, linux-sound@vger.kernel.org, tiwai@suse.com,
	perex@perex.cz, co+24304d323d28f156@bugs.sh,
	stable@vger.kernel.org
Subject: Re: [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes
Date: Mon, 28 Sep 2026 13:10:57 +0200	[thread overview]
Message-ID: <878q4l7hry.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260918225753.1278505-1-xmei5@asu.edu>

On Sat, 19 Sep 2026 00:57:53 +0200,
Xiang Mei wrote:
> 
> detect_usb_format() cross-checks bSubframeSize, bBitResolution and
> tSamFreq between the capture and playback interfaces, but never relates
> the two endpoints' wMaxPacketSize and bNrChannels.  Each playback URB
> gets a buffer of ua->playback.max_packet_bytes, while the number of
> bytes written into it is derived from the capture stream:
> capture_urb_complete() computes frames from the received capture packet
> and capture.frame_bytes, and start_usb_playback() and playback_work()
> multiply that by playback.frame_bytes.
> 
> A device declaring a large capture wMaxPacketSize with few capture
> channels and a small playback wMaxPacketSize with many playback channels
> therefore memset()s and memcpy()s past the end of the playback buffer,
> in open() of the PCM node the driver registers during probe.
> usb_submit_urb() rejects the over-long iso_frame_desc[0].length with
> -EMSGSIZE, but only after the write.
> 
> Reject such descriptors at probe time.  Genuine UA-101/UA-1000 hardware
> declares proportional packet sizes and is unaffected.
> 
>   BUG: KASAN: slab-out-of-bounds in start_usb_playback (sound/usb/misc/ua101.c:586)
>   Write of size 2048 at addr ffff8881098f3c00 by task exploit/5021
>   Call Trace:
>    __asan_memset (mm/kasan/shadow.c:84)
>    start_usb_playback (sound/usb/misc/ua101.c:586)
>    playback_pcm_open (sound/usb/misc/ua101.c:679)
>    snd_pcm_open_substream (sound/core/pcm_native.c:2829)
>    snd_pcm_open (sound/core/pcm_native.c:2865 sound/core/pcm_native.c:2932)
>    snd_pcm_playback_open (sound/core/pcm_native.c:2891)
>    snd_open (sound/core/sound.c:166)
>    chrdev_open (fs/char_dev.c:411)
>    do_dentry_open (fs/open.c:996)
>    vfs_open (fs/open.c:1101)
>    path_openat (fs/namei.c:4837 fs/namei.c:5000)
>    do_file_open (fs/namei.c:5029)
>    do_sys_openat2 (fs/open.c:1417)
>    __x64_sys_openat (fs/open.c:1423 fs/open.c:1439 fs/open.c:1434)
>    do_syscall_64 (arch/x86/entry/syscall_64.c:61 arch/x86/entry/syscall_64.c:84)
>    entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
> 
>   The buggy address belongs to the object at ffff8881098f3c00
>    which belongs to the cache kmalloc-192 of size 192
>   The buggy address is located 0 bytes inside of
>    allocated 168-byte region [ffff8881098f3c00, ffff8881098f3ca8)
> 
> Cc: stable@vger.kernel.org
> Fixes: 63978ab3e3e9 ("sound: add Edirol UA-101 support")
> Reported-by: <co+24304d323d28f156@bugs.sh>
> Assisted-by: LLM
> Signed-off-by: Xiang Mei <xmei5@asu.edu>

Applied now.  Thanks.


Takashi

      reply	other threads:[~2026-09-28 11:11 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18 22:57 [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes Xiang Mei
2026-09-28 11:10 ` Takashi Iwai [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=878q4l7hry.wl-tiwai@suse.de \
    --to=tiwai@suse.de \
    --cc=clemens@ladisch.de \
    --cc=co+24304d323d28f156@bugs.sh \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=stable@vger.kernel.org \
    --cc=tiwai@suse.com \
    --cc=xmei5@asu.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox