mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Takashi Iwai <tiwai@suse.de>
To: Xiang Mei <xmei5@asu.edu>
Cc: perex@perex.cz, tiwai@suse.com, torsten.schenk@zoho.com,
	co+855929c2df672879@bugs.sh, linux-sound@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH] ALSA: 6fire: fix OOB write from device-reported iso length
Date: Sun, 13 Sep 2026 09:06:36 +0200	[thread overview]
Message-ID: <87ld95wryb.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260913000515.2344562-1-xmei5@asu.edu>

On Sun, 13 Sep 2026 02:05:15 +0200,
Xiang Mei wrote:
> 
> usb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as
> (actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where
> actual_length is the unsigned length the device reported for the matching
> IN packet.  A packet completed with status 0 and actual_length < 4 wraps
> the subtraction to 0x7fffffec; a zero-length isochronous packet is legal
> on the bus, and the preceding loop rejects only non-zero status.  The sum
> reaches memset() on out_urb->buffer, a 4832-byte object from
> kcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).
> 
> Even without the wrap the result is out of bounds: at 88.2/96 kHz the
> 4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight
> packets span 5024 bytes of that buffer.  usb_submit_urb() rejects an
> over-long descriptor only after the memset() and the
> usb6fire_pcm_playback() copy of user PCM data have run.
> 
> Guard the subtraction as the sibling usb6fire_pcm_capture() already does,
> and clamp to rt->out_packet_size, the OUT endpoint's wMaxPacketSize,
> which bounds total_length by the buffer size.
> 
>   BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
>   Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018
>   Call Trace:
>    dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
>    print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
>    kasan_report (mm/kasan/report.c:595)
>    kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)
>    __asan_memset (mm/kasan/shadow.c:84)
>    usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
>    __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
>    usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
>    vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242)
>    kthread (kernel/kthread.c:436)
>    ret_from_fork (arch/x86/kernel/process.c:158)
>    ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
> 
>   Allocated by task 10:
>    __kmalloc_cache_noprof (mm/slub.c:5563)
>    usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595)
>    usb6fire_chip_probe (sound/usb/6fire/chip.c:133)
>    usb_probe_interface (drivers/usb/core/driver.c:399)
> 
>   The buggy address belongs to the object at ffff88802a3d0000
>    which belongs to the cache kmalloc-8k of size 8192
>   The buggy address is located 0 bytes inside of
>    4832-byte region [ffff88802a3d0000, ffff88802a3d12e0)
>   Kernel panic - not syncing: Fatal exception in interrupt
> 
> Fixes: c6d43ba816d1 ("ALSA: usb/6fire - Driver for TerraTec DMX 6Fire USB")
> Reported-by: co+855929c2df672879@bugs.sh
> Closes: https://lore.kernel.org/all/gisnub8aWGLbyZLcDCSc7zWsHonMWGcyRgt5%40bugs.sh/
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: Xiang Mei <xmei5@asu.edu>

There has been already another fix for the packet size calculation
there in the upstream (already in Linus tree, too).
Could you check with it and rebase/resubmit if the fix is still
needed?


thanks,

Takashi

      reply	other threads:[~2026-09-13  7:06 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13  0:05 Xiang Mei
2026-09-13  7:06 ` Takashi Iwai [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87ld95wryb.wl-tiwai@suse.de \
    --to=tiwai@suse.de \
    --cc=co+855929c2df672879@bugs.sh \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=tiwai@suse.com \
    --cc=torsten.schenk@zoho.com \
    --cc=xmei5@asu.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®