The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Takashi Iwai <tiwai@suse.de>
To: Baul Lee <baul.lee@xbow.com>
Cc: g@b4.vu, perex@perex.cz, tiwai@suse.com,
	linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org,
	federico.kirschbaum@xbow.com, stable@vger.kernel.org
Subject: Re: [PATCH] ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
Date: Tue, 04 Aug 2026 18:06:07 +0200	[thread overview]
Message-ID: <875x1pj2fk.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260804123611.91715-1-baul.lee@xbow.com>

On Tue, 04 Aug 2026 14:36:11 +0200,
Baul Lee wrote:
> 
> fcp_ioctl_set_meter_map() bounds the user-supplied Level Meter map size
> by the driver's own limit of 255
> 
> 	if (map.map_size < 1 || map.map_size > 255 ||
> 	    map.meter_slots < 1 || map.meter_slots > 255)
> 		return -EINVAL;
> 
> and passes it to fcp_add_new_ctl() as the control's channel count, where
> it is stored as elem->channels.
> 
> Every control read writes into struct snd_ctl_elem_value, whose integer
> array is declared long value[128], so the limit is 128, not 255.
> fcp_meter_ctl_get() stores one 64-bit word per channel into that array
> with no bound of its own:
> 
> 	for (i = 0; i < elem->channels; i++) {
> 		int idx = private->meter_level_map[i];
> 		int value = idx < 0 ? 0 : le32_to_cpu(resp[idx]);
> 
> 		ucontrol->value.integer.value[i] = value;
> 	}
> 
> snd_ctl_elem_read_user() serves that object from
> memdup_user(_control, sizeof(*control)), 1224 bytes on LP64 out of
> kmalloc-2048.  offsetof(struct snd_ctl_elem_value, value) is 72, so
> element i is written at byte 72 + 8 * i and element 144 already lands
> past the allocation.  At map_size 255 the last store ends at byte 2112,
> 888 bytes past the object and 64 bytes into the adjacent slab object.
> The stored words come from the device and meter_level_map[] selects
> which word lands in which slot, so extent and contents are both
> controlled.
> 
> The core does not catch this.  snd_ctl_check_elem_info() is reached only
> from __snd_ctl_elem_info(), which snd_ctl_elem_read() calls under
> CONFIG_SND_CTL_DEBUG; without that option snd_ctl_skip_validation() is a
> compile-time true.  __snd_ctl_add_replace() validates kcontrol->count and
> never inspects elem->channels.
> 
> Installing an oversized map needs CAP_SYS_RAWIO, but the control outlives
> the hwdep descriptor that created it, so the out-of-bounds stores are
> issued by any process able to read controls on /dev/snd/controlC0.
> 
> KASAN on 7.2.0-rc5 (arm64), triggered by an unprivileged control read:
> 
>   BUG: KASAN: slab-out-of-bounds in fcp_meter_ctl_get
>   Write of size 8 at addr ffff000017af04c8 by task fcp_trigger/185
>    __asan_store8
>    fcp_meter_ctl_get
>    snd_ctl_elem_read
>    snd_ctl_ioctl
>   Allocated by task 185:
>    memdup_user
>    snd_ctl_ioctl
>   The buggy address is located 0 bytes to the right of
>    allocated 1224-byte region [ffff000017af0000, ffff000017af04c8)
> 
> Bound the map size by the ABI limit rather than by 255, and bound the
> store loop at the sink so it cannot run past the value array whatever
> elem->channels holds.
> 
> Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
> 
> Fixes: 46757a3e7d50 ("ALSA: FCP: Add Focusrite Control Protocol driver")
> Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
> Reported-by: Baul Lee <baul.lee@xbow.com>
> Cc: stable@vger.kernel.org
> Signed-off-by: Baul Lee <baul.lee@xbow.com>

Applied now.  Thanks.


Takashi

      reply	other threads:[~2026-08-04 16:06 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04 12:36 [PATCH] ALSA: FCP: fix OOB write in fcp_meter_ctl_get() Baul Lee
2026-08-04 16:06 ` Takashi Iwai [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=875x1pj2fk.wl-tiwai@suse.de \
    --to=tiwai@suse.de \
    --cc=baul.lee@xbow.com \
    --cc=federico.kirschbaum@xbow.com \
    --cc=g@b4.vu \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=stable@vger.kernel.org \
    --cc=tiwai@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox