mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] ALSA: line6: Clamp the playback URB size to the OUT endpoint packet size
@ 2026-09-18 21:22 Xiang Mei
  2026-09-19  0:09 ` Xiang Mei
  0 siblings, 1 reply; 2+ messages in thread
From: Xiang Mei @ 2026-09-18 21:22 UTC (permalink / raw)
  To: perex, tiwai, linux-sound
  Cc: dev, co+f595d33a1b0a565b, stable, linux-kernel, Xiang Mei

The playback buffer is sized from the OUT endpoint's max_packet_size_out,
but submit_audio_out_urb() takes the length to write into it from
prev_fsize, which audio_in_callback() derived from the IN endpoint.  Both
come from the device's own descriptors and nothing relates them, so a
device declaring a large iso IN and a small iso OUT wMaxPacketSize
overflows the buffer.  usb_submit_urb() rejects the oversized URB, but
only after the write has run.

Attaching the device is the whole trigger: toneport_startup() acquires the
monitor stream and starts both URB streams on its own, so the overflow
happens in the URB completion handler with no local process involved.

Clamp the length to max_packet_size_out.  A device whose OUT endpoint
matches the audio format it announces never reaches the limit.

BUG: KASAN: slab-out-of-bounds in submit_audio_out_urb (sound/usb/line6/playback.c:242)
Write of size 1024 at addr ffff88801b94bc00 by task vhci_rx/183

Call Trace:
 kasan_report (mm/kasan/report.c:595)
 kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)
 __asan_memset (mm/kasan/shadow.c:84)
 submit_audio_out_urb (sound/usb/line6/playback.c:242)
 audio_out_callback (sound/usb/line6/playback.c:354)
 __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
 usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
 vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)
 kthread (kernel/kthread.c:436)
 ret_from_fork (arch/x86/kernel/process.c:158)
 ret_from_fork_asm (arch/x86/entry/entry_64.S:245)

The buggy address belongs to the object at ffff88801b94bc00
 which belongs to the cache kmalloc-512 of size 512

Cc: stable@vger.kernel.org
Fixes: 7a0f55aeeb8f ("ALSA: line6: Support assymetrical in/out configurations")
Reported-by: <co+f595d33a1b0a565b@bugs.sh>
Assisted-by: LLM
Signed-off-by: Xiang Mei <xmei5@asu.edu>
---
 sound/usb/line6/playback.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/usb/line6/playback.c b/sound/usb/line6/playback.c
index 7ebaf125f969..cfb20585c5ea 100644
--- a/sound/usb/line6/playback.c
+++ b/sound/usb/line6/playback.c
@@ -181,6 +181,7 @@ static int submit_audio_out_urb(struct snd_line6_pcm *line6pcm)
 		}
 
 		fsize *= bytes_per_frame;
+		fsize = min(fsize, line6pcm->max_packet_size_out);
 
 		fout->offset = urb_size;
 		fout->length = fsize;
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] ALSA: line6: Clamp the playback URB size to the OUT endpoint packet size
  2026-09-18 21:22 [PATCH] ALSA: line6: Clamp the playback URB size to the OUT endpoint packet size Xiang Mei
@ 2026-09-19  0:09 ` Xiang Mei
  0 siblings, 0 replies; 2+ messages in thread
From: Xiang Mei @ 2026-09-19  0:09 UTC (permalink / raw)
  To: perex, tiwai, linux-sound; +Cc: dev, co+f595d33a1b0a565b, stable, linux-kernel

On Fri, Sep 18, 2026 at 2:22 PM Xiang Mei <xmei5@asu.edu> wrote:
>
> The playback buffer is sized from the OUT endpoint's max_packet_size_out,
> but submit_audio_out_urb() takes the length to write into it from
> prev_fsize, which audio_in_callback() derived from the IN endpoint.  Both
> come from the device's own descriptors and nothing relates them, so a
> device declaring a large iso IN and a small iso OUT wMaxPacketSize
> overflows the buffer.  usb_submit_urb() rejects the oversized URB, but
> only after the write has run.
>
> Attaching the device is the whole trigger: toneport_startup() acquires the
> monitor stream and starts both URB streams on its own, so the overflow
> happens in the URB completion handler with no local process involved.
>
> Clamp the length to max_packet_size_out.  A device whose OUT endpoint
> matches the audio format it announces never reaches the limit.
>
> BUG: KASAN: slab-out-of-bounds in submit_audio_out_urb (sound/usb/line6/playback.c:242)
> Write of size 1024 at addr ffff88801b94bc00 by task vhci_rx/183
>
> Call Trace:
>  kasan_report (mm/kasan/report.c:595)
>  kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)
>  __asan_memset (mm/kasan/shadow.c:84)
>  submit_audio_out_urb (sound/usb/line6/playback.c:242)
>  audio_out_callback (sound/usb/line6/playback.c:354)
>  __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
>  usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
>  vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)
>  kthread (kernel/kthread.c:436)
>  ret_from_fork (arch/x86/kernel/process.c:158)
>  ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
>
> The buggy address belongs to the object at ffff88801b94bc00
>  which belongs to the cache kmalloc-512 of size 512
>
> Cc: stable@vger.kernel.org
> Fixes: 7a0f55aeeb8f ("ALSA: line6: Support assymetrical in/out configurations")
> Reported-by: <co+f595d33a1b0a565b@bugs.sh>
> Assisted-by: LLM
> Signed-off-by: Xiang Mei <xmei5@asu.edu>
> ---
>  sound/usb/line6/playback.c | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/sound/usb/line6/playback.c b/sound/usb/line6/playback.c
> index 7ebaf125f969..cfb20585c5ea 100644
> --- a/sound/usb/line6/playback.c
> +++ b/sound/usb/line6/playback.c
> @@ -181,6 +181,7 @@ static int submit_audio_out_urb(struct snd_line6_pcm *line6pcm)
>                 }
>
>                 fsize *= bytes_per_frame;
> +               fsize = min(fsize, line6pcm->max_packet_size_out);
>
>                 fout->offset = urb_size;
>                 fout->length = fsize;
> --
> 2.43.0
>

Please disregard this patch. It duplicates my other submission
addressing the same out-of-bounds write in submit_audio_out_urb().

Sorry for the duplicate submission and noise.

Thanks,
Xiang

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-19  0:09 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-18 21:22 [PATCH] ALSA: line6: Clamp the playback URB size to the OUT endpoint packet size Xiang Mei
2026-09-19  0:09 ` Xiang Mei

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®