* [PATCH] ALSA: ua101: Reject too-short USB descriptors
@ 2026-05-19 3:32 Cássio Gabriel
2026-05-19 6:09 ` Takashi Iwai
0 siblings, 1 reply; 2+ messages in thread
From: Cássio Gabriel @ 2026-05-19 3:32 UTC (permalink / raw)
To: Takashi Iwai, Clemens Ladisch, Jaroslav Kysela
Cc: linux-sound, linux-kernel, stable, Cássio Gabriel
find_format_descriptor() walks the class-specific interface extras by
advancing with bLength. It rejects descriptors that extend past the
remaining buffer, but it does not reject descriptor lengths smaller than
a USB descriptor header.
Reject too-short descriptors before using bLength to advance the local
scan. This keeps the UA-101 parser robust against malformed descriptor
data and matches the usual USB descriptor walking rules.
Fixes: 63978ab3e3e9 ("sound: add Edirol UA-101 support")
Cc: stable@vger.kernel.org
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
---
sound/usb/misc/ua101.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/sound/usb/misc/ua101.c b/sound/usb/misc/ua101.c
index d129b42eb979..b9a62e94e06c 100644
--- a/sound/usb/misc/ua101.c
+++ b/sound/usb/misc/ua101.c
@@ -894,8 +894,9 @@ find_format_descriptor(struct usb_interface *interface)
struct uac_format_type_i_discrete_descriptor *desc;
desc = (struct uac_format_type_i_discrete_descriptor *)extra;
- if (desc->bLength > extralen) {
- dev_err(&interface->dev, "descriptor overflow\n");
+ if (desc->bLength < sizeof(struct usb_descriptor_header) ||
+ desc->bLength > extralen) {
+ dev_err(&interface->dev, "invalid descriptor length\n");
return NULL;
}
if (desc->bLength == UAC_FORMAT_TYPE_I_DISCRETE_DESC_SIZE(1) &&
---
base-commit: 7c94f5e77906abd7b9ba81875ae238c802a187cb
change-id: 20260429-alsa-ua101-desc-len-7c4708724604
Best regards,
--
Cássio Gabriel <cassiogabrielcontato@gmail.com>
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] ALSA: ua101: Reject too-short USB descriptors
2026-05-19 3:32 [PATCH] ALSA: ua101: Reject too-short USB descriptors Cássio Gabriel
@ 2026-05-19 6:09 ` Takashi Iwai
0 siblings, 0 replies; 2+ messages in thread
From: Takashi Iwai @ 2026-05-19 6:09 UTC (permalink / raw)
To: Cássio Gabriel
Cc: Takashi Iwai, Clemens Ladisch, Jaroslav Kysela, linux-sound,
linux-kernel, stable
On Tue, 19 May 2026 05:32:15 +0200,
Cássio Gabriel wrote:
>
> find_format_descriptor() walks the class-specific interface extras by
> advancing with bLength. It rejects descriptors that extend past the
> remaining buffer, but it does not reject descriptor lengths smaller than
> a USB descriptor header.
>
> Reject too-short descriptors before using bLength to advance the local
> scan. This keeps the UA-101 parser robust against malformed descriptor
> data and matches the usual USB descriptor walking rules.
>
> Fixes: 63978ab3e3e9 ("sound: add Edirol UA-101 support")
> Cc: stable@vger.kernel.org
> Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Applied now. Thanks.
Takashi
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-05-19 6:09 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-05-19 3:32 [PATCH] ALSA: ua101: Reject too-short USB descriptors Cássio Gabriel
2026-05-19 6:09 ` Takashi Iwai
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®