Re: [PATCH] ALSA: seq: Don't leak the extension cell pointer in the bounce payload
Takashi Iwai <[email protected]>
| Newsgroups | gmane.linux.sound,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 11 Aug 2026 15:18:35 +0200,
HyeongJun An wrote:
>
> The bounce_error_event() embeds the failed event in the bounce payload
> by pointing data.ext.ptr at it. When that event is a queued
> variable-length event, its own data.ext.ptr holds the address of its
> first extension cell, put there by snd_seq_event_dup(). The payload
> goes out verbatim through snd_seq_expand_var_event(), so the address
> reaches userspace.
>
> That is the same address commit 705dd6dcbc0e ("ALSA: seq: Clear
> variable event pointer on read") removed from the event header. The
> read path still clears it there, just above the call that expands the
> payload.
>
> Embed a sanitised copy instead, treated exactly as snd_seq_read()
> treats the header. A stack copy is enough because delivery is
> synchronous and snd_seq_event_dup() copies before returning.
>
> An unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE,
> queueing a variable-length event to a port that does not exist and
> reading the bounce back. Eight bytes on 64-bit, from its own pool.
>
> Fixes: efc86691e4d8 ("ALSA: seq: Fix kernel heap address leak in bounce_error_event()")
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: HyeongJun An <[email protected]>
Applied now to for-next branch now.
> ---
> Unrelated, and not part of the change: the payload does not match struct
> snd_seq_event_bounce in include/uapi/sound/asequencer.h - the err field is
> not sent. Nothing regressed, since the kernel never produced the event
> before efc86691e4d8. I can fix that separately if you want it.
Any further fix would be appreciated.
thanks,
Takashi