Re: [PATCH] ALSA: usb-audio: fix stack info leak in RME Digiface status

Takashi Iwai <[email protected]>
Newsgroups org.kernel.vger.linux-sound,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On Sun, 26 Jul 2026 08:50:20 +0200,
Baul Lee wrote:
> 
> snd_rme_digiface_read_status() reads a four-word status block from the
> device into an uninitialised on-stack __le32 buf[4] and, whenever the
> vendor control-IN transfer does not return a negative error, copies all
> four words into the caller's status[].
> 
> snd_usb_ctl_msg() copies the full requested size back into the caller's
> buffer regardless of how many bytes the data stage actually delivered:
> 
> 	buf = kmemdup(data, size, GFP_KERNEL);
> 	err = usb_control_msg(dev, pipe, request, requesttype,
> 			      value, index, buf, size, timeout);
> 	memcpy(data, buf, size);
> 
> usb_control_msg() returns the transferred length on a short control-IN,
> which is a non-negative value, and writes only that many bytes.  The
> remainder of the copy back is the kmemdup()ed image of the caller's
> buffer, so a device answering with a short data stage leaves the
> trailing words of buf[] holding leftover kernel stack.  The only guard
> in the caller is err < 0, so those words are stored into status[].
> 
> They then reach user space: snd_rme_digiface_get_status_val() selects a
> 16-bit halfword of status[] per the control's reg/mask, and the eight
> Digiface status controls together expose the whole 16-byte frame to an
> unprivileged reader of /dev/snd/controlC*.
> 
> Zero-initialise the buffer so a short read yields zeros instead of stack
> residue.  This mirrors snd_rme_get_status1(), which already clears its
> output word before the same kind of vendor read.
> 
> Discovered by XBOW, triaged by Baul Lee <[email protected]>
> 
> Fixes: 611a96f6acf2 ("ALSA: usb-audio: Add mixer quirk for RME Digiface USB")
> Reported-by: Federico Kirschbaum <[email protected]>
> Reported-by: Baul Lee <[email protected]>
> Cc: [email protected]
> Signed-off-by: Baul Lee <[email protected]>

Applied now.  Thanks.


Takashi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.