Re: [PATCH] ALSA: usx2y: bound the hwdep mmap fault offset

Takashi Iwai <[email protected]> Wed, 05 Aug 2026 09:36:13 +0200
Newsgroups org.kernel.vger.linux-sound,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On Wed, 05 Aug 2026 03:34:45 +0200,
Baul Lee wrote:
> 
> snd_us428ctls_vm_fault() turns the faulting page offset into a kernel
> address with no bound of any kind:
> 
> 	offset = vmf->pgoff << PAGE_SHIFT;
> 	vaddr = (char *)(...)->us428ctls_sharedmem + offset;
> 	page = virt_to_page(vaddr);
> 	get_page(page);
> 	vmf->page = page;
> 
> 	return 0;
> 
> snd_us428ctls_mmap() checks only the length of the mapping, never the
> offset, and us428ctls_sharedmem is a single page from
> alloc_pages_exact().  For a character device file_mmap_size_max()
> returns ULONG_MAX, so the mm layer imposes no ceiling either.  Every page
> offset above zero resolves to a struct page outside the object, and the
> handler installs it into the caller's address space read-write; the vma
> is not marked read-only.
> 
> The caller picks the page frame with a single mmap() argument and gets
> read-write access to a page of kernel memory it does not own; an offset
> that lands in an unpopulated vmemmap region oopses instead.
> 
> A process that can open the hwdep node of an attached US-X2Y reaches
> this after loading the FPGA image through the same node; no capability
> check is involved.
> 
> On 7.2.0-rc5 (arm64), mmap() with a large offset:
> 
>   Unable to handle kernel paging request at virtual address fffffdffc45d5ac8
>   pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]
>   Call trace:
>    snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]
>    __do_fault
>    __handle_mm_fault
>    handle_mm_fault
>    el0_da
> 
> Reject any offset outside the shared region.  The pcm hwdep handler in
> usx2yhwdeppcm.c computes its address the same way and needs the same
> bound.
> 
> Discovered by XBOW, triaged by Baul Lee <[email protected]>
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Reported-by: Federico Kirschbaum <[email protected]>
> Reported-by: Baul Lee <[email protected]>
> Cc: [email protected]
> Signed-off-by: Baul Lee <[email protected]>

Applied now.  Thanks.


Takashi