Re: [PATCH] ALSA: seq: Don't leak the extension cell pointer in the bounce payload

Takashi Iwai <[email protected]>
Newsgroups gmane.linux.sound,gmane.linux.kernel
Message-ID <[email protected]>
On Tue, 11 Aug 2026 15:18:35 +0200,
HyeongJun An wrote:
> 
> The bounce_error_event() embeds the failed event in the bounce payload
> by pointing data.ext.ptr at it.  When that event is a queued
> variable-length event, its own data.ext.ptr holds the address of its
> first extension cell, put there by snd_seq_event_dup().  The payload
> goes out verbatim through snd_seq_expand_var_event(), so the address
> reaches userspace.
> 
> That is the same address commit 705dd6dcbc0e ("ALSA: seq: Clear
> variable event pointer on read") removed from the event header.  The
> read path still clears it there, just above the call that expands the
> payload.
> 
> Embed a sanitised copy instead, treated exactly as snd_seq_read()
> treats the header.  A stack copy is enough because delivery is
> synchronous and snd_seq_event_dup() copies before returning.
> 
> An unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE,
> queueing a variable-length event to a port that does not exist and
> reading the bounce back.  Eight bytes on 64-bit, from its own pool.
> 
> Fixes: efc86691e4d8 ("ALSA: seq: Fix kernel heap address leak in bounce_error_event()")
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: HyeongJun An <[email protected]>

Applied now to for-next branch now.

> ---
> Unrelated, and not part of the change: the payload does not match struct
> snd_seq_event_bounce in include/uapi/sound/asequencer.h - the err field is
> not sent.  Nothing regressed, since the kernel never produced the event
> before efc86691e4d8.  I can fix that separately if you want it.

Any further fix would be appreciated.


thanks,

Takashi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.