Re: [PATCH] ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()

Takashi Iwai <[email protected]>
Newsgroups org.kernel.vger.linux-kernel,org.kernel.vger.linux-sound
Message-ID <[email protected]>
On Sun, 23 Aug 2026 15:55:48 +0200,
Marouane El Moufid wrote:
> 
> snd_usbmidi_novation_output() lays out a two-byte header at
> transfer_buffer[0..1] and passes &transfer_buffer[2] together with a
> length of ep->max_transfer - 2 to snd_rawmidi_transmit():
> 
> 	count = snd_rawmidi_transmit(ep->ports[0].substream,
> 				     &transfer_buffer[2],
> 				     ep->max_transfer - 2);
> 
> ep->max_transfer comes from the output endpoint's wMaxPacketSize via
> usb_maxpacket(). A malformed or malicious device can advertise a bulk
> OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this
> value downwards - so ep->max_transfer becomes 1 and the count argument
> becomes -1.
> 
> snd_rawmidi_transmit() passes the negative count on to
> __snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count"
> leaves count1 negative; get_aligned_size() keeps it negative for a
> byte-stream substream, so the following memcpy(buffer, ..., count1) runs
> with a (size_t)-1 length and writes far past the transfer buffer, which
> was allocated with usb_alloc_coherent(ep->max_transfer).
> 
> This is the same class of bug that was fixed for snd_usbmidi_akai_output()
> in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in
> snd_usbmidi_akai_output()"); the novation output routine was left
> unguarded. Bail out when the endpoint cannot hold the two-byte header
> plus at least one payload byte.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: [email protected]
> Signed-off-by: Marouane El Moufid <[email protected]>

Applied now.  Thanks.


Takashi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.