Re: [PATCH 0/6] ALSA: sound/core: fix multiple data races and bugs

Omer Cohen <[email protected]> Thu, 2 Jul 2026 10:41:29 +0300
Newsgroups org.alsa-project.alsa-devel
Message-ID <CAN8_ozgL3V8YAj+gsb31t3tLqWCTaVwvQROcMiNtVWWzSYqOQw@mail.gmail.com>
Hi Takashi,

Got it. I'll resubmit to linux-sound and check the latest tree.

Thanks!

On Thu, 2 Jul 2026 at 10:30 Takashi Iwai <[email protected]> wrote:

> On Fri, 26 Jun 2026 15:47:03 +0200,
> Omer Cohen wrote:
> >
> > To: Takashi Iwai <[email protected]>, Mark Brown <[email protected]>
> > Cc: [email protected]
> > Cc: [email protected]
> >
> > Hi Takashi, Mark,
> >
> > This is my first patch series to the Linux kernel.  I am CCing the
> > security team as recommended by the docs for initial reports.
> >
> > This series fixes 6 bugs found via code review and KCSAN dynamic
> > analysis in the ALSA sound/core subsystem.  All patches are against
> > current HEAD (4edcdefd4083).
> >
> > Patch 1 is confirmed with KCSAN.  The remaining patches address bugs
> > found during analysis of the same code paths.
> >
> > This work was AI-assisted.  Per the kernel documentation on reporting
> > security bugs, it is sent to the public mailing list.  All
> > reproducers have been tested on arm64 QEMU.
>
> Maybe my previous mail didn't reach you properly, so I ask here again
> (with keeping Cc at this time):
> could you resubmit to [email protected] ML, Cc to
> [email protected], instead?  Since some time ago,
> alsa-devel ML is only for user-space stuff, and the kernel patches
> should go to linux-sound ML.
>
> Also, please double-check that the issue is still reproducible with
> the latest Linus tree beforehand, too.
>
>
> thanks,
>
> Takashi
>
> >
> > Summary:
> >
> >   [1/6] ALSA: compress: remove illegal state mutation in poll()
> >     snd_compr_poll() writes runtime->state = SETUP when it sees
> >     DRAINING.  This races with snd_compress_wait_for_drain() which
> >     reads runtime->state concurrently.  KCSAN confirms:
> >
> >       BUG: KCSAN: data-race in snd_compr_poll /
> snd_compress_wait_for_drain
> >
> >       write to 0xffff0000c75c8200 of 4 bytes by task 282 on cpu 3:
> >        snd_compr_poll+0x29c/0x2c8
> >        do_sys_poll+0x2b0/0x628
> >
> >       read to 0xffff0000c75c8200 of 4 bytes by task 279 on cpu 1:
> >        snd_compress_wait_for_drain+0xa4/0x270
> >        snd_compr_ioctl+0x1ba0/0x1bc8
> >
> >       value changed: 0x00000005 -> 0x00000001
> >
> >     poll() is a query operation and must not mutate state.  The
> >     DRAINING->SETUP transition is already handled by drivers via
> >     snd_compr_drain_notify().
> >
> >   [2/6] ALSA: compress: fix buffer leak on set_params driver failure
> >     If ops->set_params() fails after buffer allocation, the buffer
> >     leaks on retry because runtime->buffer was already overwritten.
> >
> >   [3/6] ALSA: timer: fix lockless tu->tread read in read()
> >     snd_timer_user_read() reads tu->tread without ioctl_lock to
> >     determine entry size, then re-reads it under lock for the copy
> >     format.  A concurrent TREAD ioctl can change the format between
> >     reads, causing a size/format mismatch.
> >
> >   [4/6] ALSA: timer: copy queue entries under lock before copy_to_user
> >     After dequeuing under qlock, read() drops the lock and calls
> >     copy_to_user() directly from the queue slot.  Timer callbacks
> >     can overwrite that slot via queue wraparound during the copy.
> >     Same bug class as CVE-2017-1000380.
> >
> >   [5/6] ALSA: pcm: use locked state read in snd_pcm_drop()
> >     snd_pcm_drop() reads runtime->state without the stream lock.
> >     Commit 7bc02ab446d3 fixed this pattern in read/write paths
> >     but missed drop().
> >
> >   [6/6] ALSA: rawmidi: propagate resize_runtime_buffer() error
> >     snd_rawmidi_input_params() ignores the return value from
> >     resize_runtime_buffer() and unconditionally returns 0.
> >
> > KCSAN reproducer for patch 1:
> >
> >   The race is triggered by concurrent poll() and DRAIN ioctl on a
> >   compress offload stream.  A minimal reproducer uses four threads:
> >
> >     Thread 1: DRAIN ioctl loop
> >     Thread 2: PARTIAL_DRAIN ioctl loop
> >     Thread 3: STOP ioctl loop (random delay)
> >     Thread 4: poll() loop
> >
> >   The main thread repeatedly sets up and starts the stream.  With
> >   CONFIG_KCSAN=y and CONFIG_KCSAN_STRICT=y, the race is flagged
> >   within ~2000 iterations.
> >
> >   Any compress offload driver (hardware or virtual) exposes the
> >   race since the bug is in the framework, not driver code.
> >
> >   Tested on arm64 QEMU, kernel 7.1.0-rc7+ (4edcdefd4083).
> >
> > Thanks,
> > Omer
>