* [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes
@ 2026-09-18 22:57 Xiang Mei
2026-09-28 11:10 ` Takashi Iwai
0 siblings, 1 reply; 2+ messages in thread
From: Xiang Mei @ 2026-09-18 22:57 UTC (permalink / raw)
To: clemens, linux-sound, tiwai, perex; +Cc: co+24304d323d28f156, stable, Xiang Mei
detect_usb_format() cross-checks bSubframeSize, bBitResolution and
tSamFreq between the capture and playback interfaces, but never relates
the two endpoints' wMaxPacketSize and bNrChannels. Each playback URB
gets a buffer of ua->playback.max_packet_bytes, while the number of
bytes written into it is derived from the capture stream:
capture_urb_complete() computes frames from the received capture packet
and capture.frame_bytes, and start_usb_playback() and playback_work()
multiply that by playback.frame_bytes.
A device declaring a large capture wMaxPacketSize with few capture
channels and a small playback wMaxPacketSize with many playback channels
therefore memset()s and memcpy()s past the end of the playback buffer,
in open() of the PCM node the driver registers during probe.
usb_submit_urb() rejects the over-long iso_frame_desc[0].length with
-EMSGSIZE, but only after the write.
Reject such descriptors at probe time. Genuine UA-101/UA-1000 hardware
declares proportional packet sizes and is unaffected.
BUG: KASAN: slab-out-of-bounds in start_usb_playback (sound/usb/misc/ua101.c:586)
Write of size 2048 at addr ffff8881098f3c00 by task exploit/5021
Call Trace:
__asan_memset (mm/kasan/shadow.c:84)
start_usb_playback (sound/usb/misc/ua101.c:586)
playback_pcm_open (sound/usb/misc/ua101.c:679)
snd_pcm_open_substream (sound/core/pcm_native.c:2829)
snd_pcm_open (sound/core/pcm_native.c:2865 sound/core/pcm_native.c:2932)
snd_pcm_playback_open (sound/core/pcm_native.c:2891)
snd_open (sound/core/sound.c:166)
chrdev_open (fs/char_dev.c:411)
do_dentry_open (fs/open.c:996)
vfs_open (fs/open.c:1101)
path_openat (fs/namei.c:4837 fs/namei.c:5000)
do_file_open (fs/namei.c:5029)
do_sys_openat2 (fs/open.c:1417)
__x64_sys_openat (fs/open.c:1423 fs/open.c:1439 fs/open.c:1434)
do_syscall_64 (arch/x86/entry/syscall_64.c:61 arch/x86/entry/syscall_64.c:84)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
The buggy address belongs to the object at ffff8881098f3c00
which belongs to the cache kmalloc-192 of size 192
The buggy address is located 0 bytes inside of
allocated 168-byte region [ffff8881098f3c00, ffff8881098f3ca8)
Cc: stable@vger.kernel.org
Fixes: 63978ab3e3e9 ("sound: add Edirol UA-101 support")
Reported-by: <co+24304d323d28f156@bugs.sh>
Assisted-by: LLM
Signed-off-by: Xiang Mei <xmei5@asu.edu>
---
sound/usb/misc/ua101.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/sound/usb/misc/ua101.c b/sound/usb/misc/ua101.c
index b9a62e94e06c..2f0f4233380c 100644
--- a/sound/usb/misc/ua101.c
+++ b/sound/usb/misc/ua101.c
@@ -1002,6 +1002,15 @@ static int detect_usb_format(struct ua101 *ua)
}
ua->playback.usb_pipe = usb_sndisocpipe(ua->dev, usb_endpoint_num(epd));
ua->playback.max_packet_bytes = usb_endpoint_maxp(epd);
+
+ if (ua->capture.max_packet_bytes / ua->capture.frame_bytes *
+ ua->playback.frame_bytes > ua->playback.max_packet_bytes) {
+ dev_err(&ua->dev->dev,
+ "playback packet size %u too small for %u capture frames\n",
+ ua->playback.max_packet_bytes,
+ ua->capture.max_packet_bytes / ua->capture.frame_bytes);
+ return -ENXIO;
+ }
return 0;
}
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes
2026-09-18 22:57 [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes Xiang Mei
@ 2026-09-28 11:10 ` Takashi Iwai
0 siblings, 0 replies; 2+ messages in thread
From: Takashi Iwai @ 2026-09-28 11:10 UTC (permalink / raw)
To: Xiang Mei; +Cc: clemens, linux-sound, tiwai, perex, co+24304d323d28f156, stable
On Sat, 19 Sep 2026 00:57:53 +0200,
Xiang Mei wrote:
>
> detect_usb_format() cross-checks bSubframeSize, bBitResolution and
> tSamFreq between the capture and playback interfaces, but never relates
> the two endpoints' wMaxPacketSize and bNrChannels. Each playback URB
> gets a buffer of ua->playback.max_packet_bytes, while the number of
> bytes written into it is derived from the capture stream:
> capture_urb_complete() computes frames from the received capture packet
> and capture.frame_bytes, and start_usb_playback() and playback_work()
> multiply that by playback.frame_bytes.
>
> A device declaring a large capture wMaxPacketSize with few capture
> channels and a small playback wMaxPacketSize with many playback channels
> therefore memset()s and memcpy()s past the end of the playback buffer,
> in open() of the PCM node the driver registers during probe.
> usb_submit_urb() rejects the over-long iso_frame_desc[0].length with
> -EMSGSIZE, but only after the write.
>
> Reject such descriptors at probe time. Genuine UA-101/UA-1000 hardware
> declares proportional packet sizes and is unaffected.
>
> BUG: KASAN: slab-out-of-bounds in start_usb_playback (sound/usb/misc/ua101.c:586)
> Write of size 2048 at addr ffff8881098f3c00 by task exploit/5021
> Call Trace:
> __asan_memset (mm/kasan/shadow.c:84)
> start_usb_playback (sound/usb/misc/ua101.c:586)
> playback_pcm_open (sound/usb/misc/ua101.c:679)
> snd_pcm_open_substream (sound/core/pcm_native.c:2829)
> snd_pcm_open (sound/core/pcm_native.c:2865 sound/core/pcm_native.c:2932)
> snd_pcm_playback_open (sound/core/pcm_native.c:2891)
> snd_open (sound/core/sound.c:166)
> chrdev_open (fs/char_dev.c:411)
> do_dentry_open (fs/open.c:996)
> vfs_open (fs/open.c:1101)
> path_openat (fs/namei.c:4837 fs/namei.c:5000)
> do_file_open (fs/namei.c:5029)
> do_sys_openat2 (fs/open.c:1417)
> __x64_sys_openat (fs/open.c:1423 fs/open.c:1439 fs/open.c:1434)
> do_syscall_64 (arch/x86/entry/syscall_64.c:61 arch/x86/entry/syscall_64.c:84)
> entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
>
> The buggy address belongs to the object at ffff8881098f3c00
> which belongs to the cache kmalloc-192 of size 192
> The buggy address is located 0 bytes inside of
> allocated 168-byte region [ffff8881098f3c00, ffff8881098f3ca8)
>
> Cc: stable@vger.kernel.org
> Fixes: 63978ab3e3e9 ("sound: add Edirol UA-101 support")
> Reported-by: <co+24304d323d28f156@bugs.sh>
> Assisted-by: LLM
> Signed-off-by: Xiang Mei <xmei5@asu.edu>
Applied now. Thanks.
Takashi
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-28 11:11 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-18 22:57 [PATCH] ALSA: ua101: reject mismatched capture/playback packet sizes Xiang Mei
2026-09-28 11:10 ` Takashi Iwai
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox