From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f50.google.com (mail-qv1-f50.google.com [209.85.219.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA4242EACF9 for ; Thu, 18 Jun 2026 02:52:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781751131; cv=none; b=nqf7WcJiB5e0sLJPu9QLBuZ9KKau3AEYZPC88tj9DhK7XwERTDCFFAxm+BpHb2UmWY233vQivw0nDF0eJJoP8o46BACI7t4dyPwRbN9VVhsbbjlOpThrcfK7L4GuarolUcZ3KdS8ImaQ2e4Y0ElOH3K735dbGF5fyVfK2LioHww= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781751131; c=relaxed/simple; bh=uFI4CbaVHbw7LY/kwNVwR1mG+tDSp9TjV/HGSQ8Xpbk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=olCvn6t4zfiW5V3msyow9d2Fc5esjJOE2nhmUrWxYM/hwKjTGNfrXa4jXzc93o5OdyhZP2sRNw2u2jkFJ9aRfwKAbIuMM0ZcVpw2sN2gkuz4VF7exOBNDBybZGSJiF6uplJlMSJR9TXi+0ou/F7e9uvRZjHzfdmWJH4Uyw3GIyg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RN5ew6gd; arc=none smtp.client-ip=209.85.219.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RN5ew6gd" Received: by mail-qv1-f50.google.com with SMTP id 6a1803df08f44-8cceaacd07bso4188686d6.3 for ; Wed, 17 Jun 2026 19:52:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781751130; x=1782355930; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=zNhazWWKRcLlrWnSm3UA/eAJwz8pGaK0KJHTqjj4RSA=; b=RN5ew6gdenIg1iqlSKygLE1TV5rK2m0vPkAOtvrwlPUCBjQGXRAkWeOLeInvu4BIIX HquYrCmTYDi5L7lWPXMZFBTRRJW6O+mTe5SygQ25YO9CafofsjxhK80hMEA6tw/PHoPJ b15teHI4S6I5HWPGjzYtUNKYNnnUrLM5ZSjQfePNWTjAlfJUlgdBquJHj7TtfIjviwDL o1p2SHbwftyiJk3N/FtpiJML3mCTgjgkA8oUmYnKTmRyg0rJvvVLDSUN4VPWw/Lg40Lw wAlY9bHGxwbX55do9jc0l1HwTeXCsjKpjc0a7aeJGffBOWBJBoQ32YInGJ1vSkaPcwxP sByw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781751130; x=1782355930; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=zNhazWWKRcLlrWnSm3UA/eAJwz8pGaK0KJHTqjj4RSA=; b=WOwXyBsMHSPn0RTV+qNHxJkpi19fN+CUjy9BXgfQbMX5RnPcEiPfDt/GAU20qaLd7g Z0XsCDOb2o88Qz8xifCLn1rqM91JdP34/BzCltJhKOHQpmLqHTrAOIRJX24R2nZ33tat LAKDVVrSfMVLGrxmR/pFULMsTaw6O2cL3bXYB8DUf2cBcqgaBq7p3gI6UzBrPr6NUjtA 2+1mpUkFlO0V6Ur//WBqBtSPa+LaXObbUzs8NFEIfImZRoE5+E+TBE6eUWtlBt93zusD u57Cm214ZbOZcpN1TiA8r0KjUJR3W2eQiaYVu6CN3j+LMpPYCYQGW1+5AYB4sFOHCWTH W8Tw== X-Forwarded-Encrypted: i=1; AFNElJ/hKPYKH+Ona2yGhoisFihkDZ44ZtDwOaBPuD3QbycOtC91mdBqR3vOrko+cymzQZ0x2q8MW45a06ZjWWQ=@vger.kernel.org X-Gm-Message-State: AOJu0Yzv2tfCT9oYIACmWR4F9yDevC2SuvCRf6YR5GMrwwMZHWIfe9Tp ouTTmfsTSNPK9nVdaaU4qrAo92sHg4KL/CfA9seu64DwxqXzqVXCkPH4 X-Gm-Gg: AfdE7cns4iZaBXFejAlM2LTN6MLUwfooYjgzwbk1TA0mA1egVk3Wvz8ZEoEVKiPnYoC Gvaw7aRhRCmo7t/2gBAfUXEoHAx0+LwlcVDwkqVfglVwLXsrBsg0qjcqEf8nroEwr0jAFpCgS1E qDN+ijAwdXs+VxZMgELO+bkYPMnrp2C4+aJDv6qoXJDH5OyLIOvGsn/8Z7g+9UJMYftPhoyDZ1H qmOnJGX698/YHqnZYUVpm0f0WsguAfljt2e9zPsaonfCyIEQwVBe0YfgYT8xF0kyoNOtGKFwNCF 69+4dnBtBZR/jxvKHcPVm/TzqlpHOYBAawiGNAOs/Zlv6pTGybyIKNp8QnkzDOw+XnZ9l7EYx+p jOiDLaP9JZmjZS8aSJk7q7bQrhzcIPLJuur1YlSJStVPPo/kziyFgUsg3uHTIb8dDNm7yentWU7 4vQvTalxeS2aWCLe+GQXUUu9/cVUhnuLGCovusKJoARq9r3+4j3fm3iBptyJc9ql1mV3T8Fsj0f 3Ed0qB1i1megBR7FFLTb2VEuUx0aBHW X-Received: by 2002:a0c:e093:0:b0:8dc:ad48:70a7 with SMTP id 6a1803df08f44-8dcad48711emr49594856d6.26.1781751129711; Wed, 17 Jun 2026 19:52:09 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8dc7f9b4b3fsm25333386d6.31.2026.06.17.19.52.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 17 Jun 2026 19:52:09 -0700 (PDT) From: Michael Bommarito To: Takashi Iwai , Jaroslav Kysela Cc: Daniel Lezcano , linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 1/2] ALSA: usb-audio: qcom: reject stream disable with no active interface Date: Wed, 17 Jun 2026 22:51:25 -0400 Message-ID: <20260618025126.1862954-2-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260618025126.1862954-1-michael.bommarito@gmail.com> References: <20260618025126.1862954-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit handle_uaudio_stream_req() resolves an interface index with info_idx_from_ifnum(), which returns -EINVAL when no interface matches. The enable branch and the response: cleanup label both guard against a negative index, but the disable branch does not: it forms info = &uadev[pcm_card_num].info[info_idx] and dereferences it. uadev[].info is a pointer allocated only when a stream is first enabled, so a negative info_idx on the disable path is unsafe in two ways: - If the card was never enabled, .info is NULL and &info[-EINVAL] is a wild pointer; reading info->data_ep_pipe faults (kernel oops). - If the card was enabled at least once (.info allocated) and the disable names an interface that does not match, &info[-EINVAL] points before the allocation; info->data_ep_pipe / info->sync_ep_pipe are an out-of-bounds slab read and, when non-zero, an out-of-bounds 4-byte write (both pipe fields are cleared to 0). That is memory corruption, not just a NULL dereference. The request is reachable from unprivileged local userspace over AF_QIPCRTR. Reject a disable request with no resolved interface, matching the guard the enable path already has. Fixes: 326bbc348298a ("ALSA: usb-audio: qcom: Introduce QC USB SND offloading support") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Michael Bommarito --- Not reproduced: static analysis against current mainline only (no Qualcomm hardware; CONFIG_SND_USB_AUDIO_QMI does not build on x86). The enable branch and the response: cleanup label already guard info_idx; this adds the same guard to the disable branch. Please confirm on a Qualcomm build whether a disable request can reach this branch with info_idx < 0, and whether the out-of-bounds write in the .info-allocated case is reachable. sound/usb/qcom/qc_audio_offload.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/sound/usb/qcom/qc_audio_offload.c b/sound/usb/qcom/qc_audio_offload.c index a3f90cc7c6cad..852a91e4b8686 100644 --- a/sound/usb/qcom/qc_audio_offload.c +++ b/sound/usb/qcom/qc_audio_offload.c @@ -1640,6 +1640,11 @@ static void handle_uaudio_stream_req(struct qmi_handle *handle, subs->opened = 0; } } else { + if (info_idx < 0) { + ret = -EINVAL; + goto response; + } + info = &uadev[pcm_card_num].info[info_idx]; if (info->data_ep_pipe) { ep = usb_pipe_endpoint(uadev[pcm_card_num].udev, -- 2.53.0