From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-dy1-f169.google.com (mail-dy1-f169.google.com [74.125.82.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 55FB53B895E for ; Thu, 8 Oct 2026 19:01:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791486083; cv=none; b=ZtD3n6f17OmyZoQ22JaJKmFuI7wywk9/ZvomOlpvZVfiH6Cx1/I7jIgsgdC25j2j2zcIfdUiZp9KUfI0/nzuSLiIAs8q2C3WrMEMG616ZoYnfVBkPCnhI54ZWr+nYA6leyVNDZ0A+7WgXLpY86w+lGf9ujNGbrZOFh816hKXf18= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791486083; c=relaxed/simple; bh=dI/ediDEtYW1zJEmi2TVBHlg+BaG4nXKtBtA6rC2rD4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=a+1IQuEUahkM2ZnMruxw4ZEXBl5jpj2lOB583Z4XMn4KvNmJyHDrE9QCw7SJrkyzpztFXY1m91STER2M1RPX+3oNLOKFyp0Op5iPJA9SlNd71xCpgMdMBML+OPxIhm3kLmKK7BHrpfH6PrD/x+E8utYw5erojssKwNCRQ+BTvG8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=Zv5xF3Wk; arc=none smtp.client-ip=74.125.82.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="Zv5xF3Wk" Received: by mail-dy1-f169.google.com with SMTP id 5a478bee46e88-30b6dad2382so7754775eec.0 for ; Thu, 08 Oct 2026 12:01:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1791486081; x=1792090881; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=wH0vSAnuTtk11qs15jI11qzpg6PrfnUwzzqFGPyRMD0=; b=Zv5xF3Wkd20FnYuORrKy04mz5wMYsFBJ+7jgdNI/IUKP3WuIcRidiv0nziZ9eklelf m4oZPV4Ns24RxBDd9lgFS3gX+W2EFGdSiEWcA9qa3jZPRxFDWh3Ll/reDSr+31j6ufca fm/ndCCKJgFKWNshElzNnrJ9mog0lRqDBZVRIs/odfEMVE5BBsv/WOFur++/QWGGsgFL kjkwkyO3Sma/CZmf9mfiA7FqTyGLI/aGNIOLsYXfw7Rp8rNcUSnQyvTBJE5oyObM2gLM ccQ+uJJ/CKGvyTH4jwh+edS1HbO/1IUt/YxBamCaDnygjbxRioEuK1thl/iT9X1X1/HM 9IwA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791486081; x=1792090881; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=wH0vSAnuTtk11qs15jI11qzpg6PrfnUwzzqFGPyRMD0=; b=dyY7nf7IZHrdSuDJwbLSgc2y+oRIReD77swX7dAWOBTJ4+rALJWK65hXPWSibLsNiB QzPA6zGx8JvrpskpGcaB9U1pX6cd4xz+9qYfbJOhi4Ien7ho2FLdYfuR2AmG8yBMXdBm pjnlVeAt9yVsgt+2kuTZka6RQ3hqCJ73d6e9wz3qqFhqgLdWDeK8N54cVODhDEc0hmw6 3u0iDs0bBO38rArayAIK2eQELjEZVhb+G9LHrEirIcMmRBJGcMne8nxe7mGoJi0bXdkD 9bZa51MfEX/4dhX5xNSFsGhUV+wcnvF65qF3tzkfJfmUmWjOdh2SZOD1QfBBcBOfXQ8W m6aw== X-Forwarded-Encrypted: i=1; AKwUvBzdfdmTcg48DL2T5AbGhLVxKeXG+csIbNVsLjceiZBfFO7N1h49mAxmXQIlff9zl3dr2tFo3MzgAVKzZVM=@vger.kernel.org X-Gm-Message-State: AFuF++kAxcwQCdiF+Hf//jSVVHIf72l3Zifx5UKGR7Uk1cPgsRKdtLsn XwL3Kvs5Ocay/mLCPmbN2Ti4/tZpzhRFFS3DkQOfUegktcQHghTMc+XdwlhwGdYRDvA= X-Gm-Gg: AYBFou3Z5kj7pUZOKxXSj3HqjtnY/XW1tIlF6MM+VEpQFxKEWXIN2ruxR7jzb3OJpmH 4MR3tIvt9nFhw9UOxmPYZII3JzoigHQKQgkRWwyJomp0bIXy71DwHieqQorytUgcu5/ARycOa6a 8cGftRSGeILI9909x9TVOCXHdEgY2w1+gKUiDecBU0DC3FDsAyl2AhnQBZdKkRrGlh6IzKKQQK+ VVKsl2i50yTvmdZ6yH43tBz+33ZInz4ifr4BE49Sl+UswE1I/9F9PwEdF7Cqxz6umHNkc/ruXfc yZY9Jdr3bqzo6KSEQ6++Nn8R/iyUXCY7wncMdFr61oPH+S9DAVhbnsoP1fCyppiIzAaCnxXiC6A 0Vx/uy4nOEhvH5DJckmc8iD9bgS3RFAbgs4DDPYamvz52X6GJIkgeIPlNIC3W4RXN2+Cr6fwb8t fei7BrjkTaj8kAZFc38/02MVXmvG/5Z8Y//GwHEKxlHZ1S3TLRKfbmUHn+FtwAGdnR4/xwXx4iY AMJdmJYNS1idqBYJkQa7slyqlO9MDPiszFRJTsNUB9EKFZIJn23DbCOsf0QVAA509Rn758= X-Received: by 2002:a05:7022:2513:b0:14b:1e78:a19f with SMTP id a92af1059eb24-161fdbedf4bmr10042490c88.6.1791486079633; Thu, 08 Oct 2026 12:01:19 -0700 (PDT) Received: from localhost.localdomain ([2603:8001:5f01:8bab:bc88:5ec1:4f8a:5b23]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3537b3eccebsm405691eec.12.2026.10.08.12.01.17 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 08 Oct 2026 12:01:18 -0700 (PDT) From: Artem Dinaburg To: stable@vger.kernel.org Cc: Artem Dinaburg , Greg Kroah-Hartman , Sasha Levin , Peter Ujfalusi , Seppo Ingalsuo , Liam Girdwood , Ranjani Sridharan , Bard Liao , Mark Brown , Pierre-Louis Bossart , Liam Girdwood , Daniel Baluta , Kai Vehmanen , Jaroslav Kysela , Takashi Iwai , sound-open-firmware@alsa-project.org, alsa-devel@alsa-project.org, linux-kernel@vger.kernel.org, Pierre-Louis Bossart , Vijendar Mukunda , linux-sound@vger.kernel.org Subject: [PATCH 6.6.y 2/2] ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers Date: Thu, 8 Oct 2026 15:01:04 -0400 Message-ID: <20261008190108.96660-3-artem@trailofbits.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20261008190108.96660-1-artem@trailofbits.com> References: <20261008190108.96660-1-artem@trailofbits.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Peter Ujfalusi [ Upstream commit 6fd60136d256b3b948333ebdb3835f41a95ab7ef ] Other, non DAI copier widgets could have the same stream name (sname) as the ALH copier and in that case the copier->data is NULL, no alh_data is attached, which could lead to NULL pointer dereference. We could check for this NULL pointer in sof_ipc4_prepare_copier_module() and avoid the crash, but a similar loop in sof_ipc4_widget_setup_comp_dai() will miscalculate the ALH device count, causing broken audio. The correct fix is to harden the matching logic by making sure that the 1. widget is a DAI widget - so dai = w->private is valid 2. the dai (and thus the copier) is ALH copier [ Backport to 6.6.y: Apply both widget-kind and ALH-type predicates to the target loops; the newer node_type local is absent and unused by this implementation. ] Fixes: a150345aa758 ("ASoC: SOF: ipc4-topology: add SoundWire/ALH aggregation support") Reported-by: Seppo Ingalsuo Link: https://github.com/thesofproject/sof/pull/9652 Signed-off-by: Peter Ujfalusi Reviewed-by: Liam Girdwood Reviewed-by: Ranjani Sridharan Reviewed-by: Bard Liao Link: https://patch.msgid.link/20250206084642.14988-1-peter.ujfalusi@linux.intel.com Signed-off-by: Mark Brown Assisted-by: LLM Signed-off-by: Artem Dinaburg --- This is patch 2 of 2 in the ordered 6.6.y backport series. This change addresses CVE-2025-21870. Limits ALH aggregation searches to DAI widgets of ALH type, preventing NULL private-data dereferences and incorrect device counts from same-name non-DAI widgets. Each loop checks WIDGET_IS_DAI() before interpreting w->private as a DAI, then checks SOF_DAI_INTEL_ALH before incrementing the device count or accessing copier data. The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y. This fix also affects 6.1.y, which will need a separate backport; this submission contains only the 6.6.y patch. sound/soc/sof/ipc4-topology.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/sound/soc/sof/ipc4-topology.c b/sound/soc/sof/ipc4-topology.c index 18096aefce13..8911c075251c 100644 --- a/sound/soc/sof/ipc4-topology.c +++ b/sound/soc/sof/ipc4-topology.c @@ -577,10 +577,16 @@ static int sof_ipc4_widget_setup_comp_dai(struct snd_sof_widget *swidget) } list_for_each_entry(w, &sdev->widget_list, list) { - if (w->widget->sname && + struct snd_sof_dai *alh_dai; + + if (!WIDGET_IS_DAI(w->id) || !w->widget->sname || strcmp(w->widget->sname, swidget->widget->sname)) continue; + alh_dai = w->private; + if (alh_dai->type != SOF_DAI_INTEL_ALH) + continue; + blob->alh_cfg.device_count++; } @@ -1692,11 +1698,13 @@ sof_ipc4_prepare_copier_module(struct snd_sof_widget *swidget, */ i = 0; list_for_each_entry(w, &sdev->widget_list, list) { - if (w->widget->sname && + if (!WIDGET_IS_DAI(w->id) || !w->widget->sname || strcmp(w->widget->sname, swidget->widget->sname)) continue; dai = w->private; + if (dai->type != SOF_DAI_INTEL_ALH) + continue; alh_copier = (struct sof_ipc4_copier *)dai->private; alh_data = &alh_copier->data; blob->alh_cfg.mapping[i].device = alh_data->gtw_cfg.node_id; -- 2.39.5