[PATCH 4/6] ALSA: timer: copy queue entries to local buffer before copy_to_user
Omer Cohen <[email protected]> Fri, 26 Jun 2026 16:47:07 +0300
| Newsgroups | org.alsa-project.alsa-devel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
snd_timer_user_read() dequeues an entry from the timer event queue
under qlock, then drops the spinlock and calls copy_to_user() directly
from the queue slot (tread = &tu->tqueue[qhead]).
While the lock is dropped, timer interrupt callbacks
(snd_timer_user_tinterrupt) can write new entries to the queue. If
enough events arrive to wrap qtail back to the dequeued slot, the
callback overwrites data that copy_to_user() is still reading.
This is the same class of bug fixed for the non-tread queue path in
CVE-2017-1000380, but the tread queue (tu->tqueue) and the NONE
format queue (tu->queue) were left with the same pattern.
Copy dequeued entries to local stack variables under the spinlock
before dropping it, then use the local copies for copy_to_user().
Fixes: d11662f4f798 ("ALSA: timer: Fix race between read and ioctl")
Cc: [email protected]
Reported-by: Omer Cohen <[email protected]>
Signed-off-by: Omer Cohen <[email protected]>
---
sound/core/timer.c | 19 +++++++++++---------
1 file changed, 10 insertions(+), 9 deletions(-)
diff --git a/sound/core/timer.c b/sound/core/timer.c
index 51c6ac4df9f4..XXXXXXXXXXXX 100644
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -2390,6 +2390,7 @@ static ssize_t snd_timer_user_read(struct file *file, char __user *buffer,
- struct snd_timer_tread64 *tread;
+ struct snd_timer_tread64 tread_local;
struct snd_timer_tread32 tread32;
+ struct snd_timer_read read_local;
struct snd_timer_user *tu;
long result = 0, unit;
int tread_format;
int qhead;
@@ -2452,23 +2454,23 @@ static ssize_t snd_timer_user_read(struct file *file, char __user *buffer,
qhead = tu->qhead++;
tu->qhead %= tu->queue_size;
tu->qused--;
+ tread_local = tu->tqueue[qhead];
+ read_local = tu->queue[qhead];
spin_unlock_irq(&tu->qlock);
- tread = &tu->tqueue[qhead];
-
switch (tread_format) {
case TREAD_FORMAT_TIME64:
- if (copy_to_user(buffer, tread,
+ if (copy_to_user(buffer, &tread_local,
sizeof(struct snd_timer_tread64)))
err = -EFAULT;
break;
case TREAD_FORMAT_TIME32:
memset(&tread32, 0, sizeof(tread32));
tread32 = (struct snd_timer_tread32) {
- .event = tread->event,
- .tstamp_sec = tread->tstamp_sec,
- .tstamp_nsec = tread->tstamp_nsec,
- .val = tread->val,
+ .event = tread_local.event,
+ .tstamp_sec = tread_local.tstamp_sec,
+ .tstamp_nsec = tread_local.tstamp_nsec,
+ .val = tread_local.val,
};
if (copy_to_user(buffer, &tread32, sizeof(tread32)))
@@ -2470,6 +2474,6 @@ static ssize_t snd_timer_user_read(struct file *file, char __user *buffer,
break;
case TREAD_FORMAT_NONE:
- if (copy_to_user(buffer, &tu->queue[qhead],
+ if (copy_to_user(buffer, &read_local,
sizeof(struct snd_timer_read)))
err = -EFAULT;
break;
--
2.43.0