Re: [PATCH] ALSA: usx2y: bound the hwdep mmap fault offset
Takashi Iwai <[email protected]> Wed, 05 Aug 2026 09:36:13 +0200
| Newsgroups | org.kernel.vger.linux-sound,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 05 Aug 2026 03:34:45 +0200, Baul Lee wrote: > > snd_us428ctls_vm_fault() turns the faulting page offset into a kernel > address with no bound of any kind: > > offset = vmf->pgoff << PAGE_SHIFT; > vaddr = (char *)(...)->us428ctls_sharedmem + offset; > page = virt_to_page(vaddr); > get_page(page); > vmf->page = page; > > return 0; > > snd_us428ctls_mmap() checks only the length of the mapping, never the > offset, and us428ctls_sharedmem is a single page from > alloc_pages_exact(). For a character device file_mmap_size_max() > returns ULONG_MAX, so the mm layer imposes no ceiling either. Every page > offset above zero resolves to a struct page outside the object, and the > handler installs it into the caller's address space read-write; the vma > is not marked read-only. > > The caller picks the page frame with a single mmap() argument and gets > read-write access to a page of kernel memory it does not own; an offset > that lands in an unpopulated vmemmap region oopses instead. > > A process that can open the hwdep node of an attached US-X2Y reaches > this after loading the FPGA image through the same node; no capability > check is involved. > > On 7.2.0-rc5 (arm64), mmap() with a large offset: > > Unable to handle kernel paging request at virtual address fffffdffc45d5ac8 > pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y] > Call trace: > snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y] > __do_fault > __handle_mm_fault > handle_mm_fault > el0_da > > Reject any offset outside the shared region. The pcm hwdep handler in > usx2yhwdeppcm.c computes its address the same way and needs the same > bound. > > Discovered by XBOW, triaged by Baul Lee <[email protected]> > > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Reported-by: Federico Kirschbaum <[email protected]> > Reported-by: Baul Lee <[email protected]> > Cc: [email protected] > Signed-off-by: Baul Lee <[email protected]> Applied now. Thanks. Takashi