From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f198.google.com (mail-pf1-f198.google.com [209.85.210.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F4C33D967A for ; Tue, 28 Jul 2026 20:17:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785269866; cv=none; b=YvrOveyQxacggErpoFZ+G9IHQCqql0lpuLqR/JOzgqsdjlJAOyM0kHlS7h4hVamCTwzQiroxefsqusG3P500Ctmsl5D1gyx7aL9Q3e2Uefcbj3AZcHoKzUMbkFz/3qCheNg+gGhzrRGDgCNDZMFdNLoX/P593aqjg+jkNWIv46E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785269866; c=relaxed/simple; bh=sjQLodJGCqV+uChLep9HZs5jqBfivMxq3Co1F+PXJIc=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=TaLPFdrIGurU8Bujg9xBorXZ3mfLrfw0cr5lQAAKAZ5264ubx7BTu2XQwIXc/CAJ0999oKsJMEZoZ4c2HVCvBvohEfOu2aAlTed4Mxbi0Z3BDY3VcFMvVVpO6dk2O4vmFjhEFpFjtYPPn2OBe1IwOlyCbs54M/igEJJBewlXDSk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--sonalipradhan.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=dH7S5t1k; arc=none smtp.client-ip=209.85.210.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--sonalipradhan.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="dH7S5t1k" Received: by mail-pf1-f198.google.com with SMTP id d2e1a72fcca58-84e13b57b2cso254776b3a.1 for ; Tue, 28 Jul 2026 13:17:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785269865; x=1785874665; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5kgrhmvADb8rlHytqLkDTPOL4OV9lgDm4ab/YstRW3M=; b=dH7S5t1kGUI2P+AVhr8uaIIrcVmm59HK+o1uk8/HyPho85JzZT2Wf38grmaWmf+XOI UK2dmlEiPhS2ssi3EcA4HZX1nQ/SRLG7fXGK1PkwHUG6xenfRXhrI4oulwpyb5gY0ztM uhZ09QCEKCJiaF8PpvVY1RLzObqaPIDXwddd9uGgLxFn9pg6+LE7mK6HOT6YL/LM65nw IMfFIJRszJGBlpMKr6nkfhZJWGwbIc05E3nzxXzhlI4p7WOxwkZibze91U3mO6kVbPw4 VS80oaHmwyDYm1RwEiXFCKyi8xkcNRNAuSia1Cn2AzBTj2q+STnU6FIRusA5t/EYLph7 B5+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785269865; x=1785874665; h=content-type:cc:to:from:subject:message-id:mime-version:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=5kgrhmvADb8rlHytqLkDTPOL4OV9lgDm4ab/YstRW3M=; b=hsQs69XN5aS2xkruqAxNS01N9No88yG2bOPXfJK6MEIdCLbrioRm9u2Q6lkmAMY2L3 s1ETSg7US/wVfKNTZ3UvKS3XIfkxkXBekFCQbXsn03hg1BGWjUNcU34+EVxIp9miSYbJ cJv+xxNrCwmNfQPX//7UBB5yeqELAvI5h6Kt/jIrHVMcEw2YNWojjuGK8nrWDLCHthm8 GMTG6dutC8fgbhTMFfzWiNQjPiHzTCb4VhuGynzorz+BOkKFDjKjYPNC3vU+bxSXE571 n4AszXJhpdme0OedASn3EcNW5BW8nWCMss4o+bm3q6L954Zjhk1h2E08KKEfy4xUAS6B AnVA== X-Forwarded-Encrypted: i=1; AHgh+Rq3c47tm7bnXzGQ/t4jSyw0Jb2/laTT0TOAknRLDLFyxKFrFw20YXRMBxwxcfq2586ZRyBitbWw/8xU268=@vger.kernel.org X-Gm-Message-State: AOJu0YyWAPOQFtdxy7rEGQq27VjOMcZh1QGsf9qeD+o6aI3KtqZYAjIo bDJJ7aWlCL9PcWWPokfKXpglQ0ntqYmLhxlfVy/Cr8yO6AP5r7ZYIHTf/dq+IwG52+NqjNVW0uz gwo/sC4PaDsm4JYsWF0RwAYcMne5/ulKv9w== X-Received: from pfbil5.prod.google.com ([2002:a05:6a00:8d45:b0:84a:3e5c:a215]) (user=sonalipradhan job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:179a:b0:847:5ec6:3afe with SMTP id d2e1a72fcca58-84e9325cc94mr3878191b3a.31.1785269864566; Tue, 28 Jul 2026 13:17:44 -0700 (PDT) Date: Tue, 28 Jul 2026 20:17:16 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.487.gaf234c4eb3-goog Message-ID: <20260728201716.2347726-1-sonalipradhan@google.com> Subject: [PATCH] ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set From: Sonali Pradhan To: Takashi Iwai , Jaroslav Kysela Cc: Daniel Mack , Gordon Chen , Kees Cook , Jussi Laako , linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Sonali Pradhan Content-Type: text/plain; charset="UTF-8" When a USB audio endpoint requests full packet transfers via the fill_max descriptor flag, data_ep_set_params() promotes ep->curpacksize to ep->maxpacksize. However, maxsize is left at the original sample-rate derived value. Since u->buffer_size is allocated as maxsize * packets, the resulting DMA buffer is far too small for the requested transfer length. When the USB host controller streams up to curpacksize bytes per packet, it writes past the end of the buffer via DMA, corrupting kernel heap memory. Update maxsize to curpacksize when fill_max is set so that the allocated DMA buffer size matches the actual transfer request size. Fixes: 8fdff6a319e7 ("ALSA: snd-usb: implement new endpoint streaming model") Cc: stable@vger.kernel.org Assisted-by: Jetski:Gemini-3.6-Flash Signed-off-by: Sonali Pradhan --- sound/usb/endpoint.c | 1 + 1 file changed, 1 insertion(+) diff --git a/sound/usb/endpoint.c b/sound/usb/endpoint.c index 24cd7692bd01..d825c09a766a 100644 --- a/sound/usb/endpoint.c +++ b/sound/usb/endpoint.c @@ -1172,6 +1172,7 @@ static int data_ep_set_params(struct snd_usb_endpoint *ep) ep->curpacksize = ep->maxpacksize; else ep->curpacksize = maxsize; + maxsize = ep->curpacksize; if (snd_usb_get_speed(chip->dev) != USB_SPEED_FULL) { packs_per_ms = 8 >> ep->datainterval; -- 2.55.0.487.gaf234c4eb3-goog