Re: [PATCH] sound: ua101: fix division by zero at probe

"M.samet Duman" <[email protected]>
Newsgroups dev.linux.lists.linux-kernel-mentees,org.kernel.vger.linux-kernel,org.kernel.vger.linux-sound,org.kernel.vger.stable
Message-ID <[email protected]>
This looks reasonable to me.

Samet
> 2026. 4. 26. 오후 2:13, SeungJu Cheon <[email protected]> 작성:
> 
> Add a missing sanity check for bNrChannels in detect_usb_format()
> to prevent a division by zero in playback_urb_complete() and
> capture_urb_complete().
> 
> USB core does not validate class-specific descriptor fields such
> as bNrChannels, so drivers must verify them before use. If a
> device provides bNrChannels = 0, frame_bytes becomes zero and is
> later used as a divisor in the URB completion handlers, leading
> to a kernel crash.
> 
> Fixes: 63978ab3e3e9 ("sound: add Edirol UA-101 support")
> Cc: [email protected]
> Signed-off-by: SeungJu Cheon <[email protected]>
> ---
> Testing:
> - dummy_hcd + raw_gadget emulating a UA-101 with bNrChannels=0.
> 
> sound/usb/misc/ua101.c | 7 +++++++
> 1 file changed, 7 insertions(+)
> 
> diff --git a/sound/usb/misc/ua101.c b/sound/usb/misc/ua101.c
> index 49b3dd8d827d..d129b42eb979 100644
> --- a/sound/usb/misc/ua101.c
> +++ b/sound/usb/misc/ua101.c
> @@ -974,6 +974,13 @@ static int detect_usb_format(struct ua101 *ua)
> 
>    ua->capture.channels = fmt_capture->bNrChannels;
>    ua->playback.channels = fmt_playback->bNrChannels;
> +    if (!ua->capture.channels || !ua->playback.channels) {
> +        dev_err(&ua->dev->dev,
> +            "invalid channel count: capture %u, playback %u\n",
> +            ua->capture.channels, ua->playback.channels);
> +        return -EINVAL;
> +    }
> +
>    ua->capture.frame_bytes =
>        fmt_capture->bSubframeSize * ua->capture.channels;
>    ua->playback.frame_bytes =
> --
> 2.52.0
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.