From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1C277341048 for ; Wed, 17 Dec 2025 09:07:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.130 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765962454; cv=none; b=hea+gVJjrKpy0Wgfcm4AkLKKQZr0v8GbfALOsmebeC51KAFV4820NI38fQLa+1bLI3MpDoeHnSJHTEW+80VWwqks3EE3Oaoh6RosTAXh59yH+48mlJmfOqGnl0D+avVWeK2cX+lNjUQpiCvrBWkjenLqtLDl1tcbUUvpr2vBoFQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765962454; c=relaxed/simple; bh=kEd4vr5Zfnix+8NBJtgdcMwgX2jJ8X2s4E1aH880Blw=; h=Date:Message-ID:From:To:Cc:Subject:In-Reply-To:References: MIME-Version:Content-Type; b=Ob+qvIPZs1tB91RhY5Yd4GM6JgAMxyxbp0E5OX+OGYt1rt3802hOEuyNpco19z4qFw6ZZQckqtiObwwKVnhceEBQ3Y17bZ6K10fIctzZpPCYnX57ksm9qoga5tNBN1pktBuYOO1A1F3IOTzeERX5WWbvKTsahMQJO3ilBfOohSs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=biRnbKjh; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=l156j0Sh; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=2WywiZdj; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=M4nz7YkV; arc=none smtp.client-ip=195.135.223.130 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="biRnbKjh"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="l156j0Sh"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="2WywiZdj"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="M4nz7YkV" Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id 071B0336C2; Wed, 17 Dec 2025 09:07:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1765962449; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=O+zLJgzkxEngLDZCT/mMUBbySSeiiGhJg+8VBTFCVpY=; b=biRnbKjhs6eHD9VhZF5yE6VfTZ6xRh6jdsoHXXton6qXmcFtB9DlGm6KMSd2sQiifL6PvG fsbacqBO6GpBTx+uYum0dxN68JA+/LC3ZKcW+mjjuP/o3kPEDo1xJykinLVATIHDN550eD hf12tmmJwjRa+vX2PRKEDfuApOjGgAs= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1765962449; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=O+zLJgzkxEngLDZCT/mMUBbySSeiiGhJg+8VBTFCVpY=; b=l156j0ShIVG9mxeUd42/MwP40SWwb+Sq/aOmwjcU4R7fU6LJgkB5Egfg98SRJqUJelBVJC g0sDVBWhupt3N+DA== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1765962448; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=O+zLJgzkxEngLDZCT/mMUBbySSeiiGhJg+8VBTFCVpY=; b=2WywiZdjugDjDa186z9zmzDN3cNZtvvOROn+6cyx5zSJRNSaTtS4kLGPPIhkZedAaUY5k8 yj/B69an7uq9O+xPgC416YyJUuwOw+b5i9mJaRKvmPjBEA719z8X1kFciHo41nz698bJz8 3D7mX0STFmyOINPVmkP3CZyFjGWVhVE= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1765962448; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=O+zLJgzkxEngLDZCT/mMUBbySSeiiGhJg+8VBTFCVpY=; b=M4nz7YkVyGcuOh0wZwM9ajlGzOkMjpch1+nHbyyRDE/YV4Vg54YWl2QvxYh5juc0GJ5v+O atILlpv54jeOy9DA== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id BA3D93EA65; Wed, 17 Dec 2025 09:07:27 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id A42bK89yQmn1UAAAD6G6ig (envelope-from ); Wed, 17 Dec 2025 09:07:27 +0000 Date: Wed, 17 Dec 2025 10:07:27 +0100 Message-ID: <87y0n1cw8g.wl-tiwai@suse.de> From: Takashi Iwai To: Shipei Qu Cc: Jaroslav Kysela , Takashi Iwai , alsa-devel@alsa-project.org, linux-kernel@vger.kernel.org, vr@darknavy.com Subject: Re: [PATCH v3] ALSA: usb-mixer: us16x08: validate meter packet indices In-Reply-To: <20251217024630.59576-1-qu@darknavy.com> References: <878qf2g0tm.wl-tiwai@suse.de> <20251217024630.59576-1-qu@darknavy.com> User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/30.1 Mule/6.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue") Content-Type: text/plain; charset=US-ASCII X-Spamd-Result: default: False [-3.26 / 50.00]; BAYES_HAM(-3.00)[99.99%]; NEURAL_HAM_LONG(-1.00)[-1.000]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM_SHORT(-0.16)[-0.781]; MIME_GOOD(-0.10)[text/plain]; FUZZY_RATELIMITED(0.00)[rspamd.com]; TO_MATCH_ENVRCPT_ALL(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; FROM_HAS_DN(0.00)[]; RCVD_TLS_ALL(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; TO_DN_SOME(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; RCVD_VIA_SMTP_AUTH(0.00)[]; RCPT_COUNT_FIVE(0.00)[6] X-Spam-Level: X-Spam-Flag: NO X-Spam-Score: -3.26 On Wed, 17 Dec 2025 03:46:30 +0100, Shipei Qu wrote: > > get_meter_levels_from_urb() parses the 64-byte meter packets sent by > the device and fills the per-channel arrays meter_level[], > comp_level[] and master_level[] in struct snd_us16x08_meter_store. > > Currently the function derives the channel index directly from the > meter packet (MUB2(meter_urb, s) - 1) and uses it to index those > arrays without validating the range. If the packet contains a > negative or out-of-range channel number, the driver may write past > the end of these arrays. > > Introduce a local channel variable and validate it before updating the > arrays. We reject negative indices, limit meter_level[] and > comp_level[] to SND_US16X08_MAX_CHANNELS, and guard master_level[] > updates with ARRAY_SIZE(master_level). > > Reported-by: DARKNAVY (@DarkNavyOrg) > Signed-off-by: Shipei Qu Applied now. Thanks. Takashi