mirror of
https://github.com/torvalds/linux.git
synced 2026-09-13 15:40:03 +02:00
ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf
The in04_last array in struct usx2ydev is declared as char[24], but
in04_buf is allocated as sizeof(struct us428_ctls) which is 21 bytes.
In i_usx2y_in04_int(), when ctl_snapshot_last == -2 (initialization
path):
memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));
This copies 24 bytes from a 21-byte slab allocation, reading 3 bytes
past the end of the source object.
Introduce a USX2Y_IN04_SIZE constant defined as sizeof(struct
us428_ctls) and use it consistently for the in04_last array, the
in04_buf allocation, the URB transfer length, and the comparison loop,
replacing the bare 24 and 21 literals throughout.
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Link: https://patch.msgid.link/20260904205826.4071119-1-tristmd@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
This commit is contained in:
parent
b26a7a80e6
commit
861111a147
|
|
@ -196,7 +196,7 @@ static void i_usx2y_in04_int(struct urb *urb)
|
|||
memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));
|
||||
us428ctls->ctl_snapshot_last = -1;
|
||||
} else {
|
||||
for (i = 0; i < 21; i++) {
|
||||
for (i = 0; i < USX2Y_IN04_SIZE; i++) {
|
||||
if (usx2y->in04_last[i] != ((char *)usx2y->in04_buf)[i]) {
|
||||
if (diff < 0)
|
||||
diff = i;
|
||||
|
|
@ -305,7 +305,7 @@ int usx2y_in04_init(struct usx2ydev *usx2y)
|
|||
goto error;
|
||||
}
|
||||
|
||||
usx2y->in04_buf = kmalloc(21, GFP_KERNEL);
|
||||
usx2y->in04_buf = kmalloc(USX2Y_IN04_SIZE, GFP_KERNEL);
|
||||
if (!usx2y->in04_buf) {
|
||||
err = -ENOMEM;
|
||||
goto error;
|
||||
|
|
@ -313,7 +313,7 @@ int usx2y_in04_init(struct usx2ydev *usx2y)
|
|||
|
||||
init_waitqueue_head(&usx2y->in04_wait_queue);
|
||||
usb_fill_int_urb(usx2y->in04_urb, usx2y->dev, usb_rcvintpipe(usx2y->dev, 0x4),
|
||||
usx2y->in04_buf, 21,
|
||||
usx2y->in04_buf, USX2Y_IN04_SIZE,
|
||||
i_usx2y_in04_int, usx2y,
|
||||
10);
|
||||
if (usb_urb_ep_type_check(usx2y->in04_urb)) {
|
||||
|
|
|
|||
|
|
@ -5,6 +5,8 @@
|
|||
#include "../midi.h"
|
||||
#include "usbus428ctldefs.h"
|
||||
|
||||
#define USX2Y_IN04_SIZE sizeof(struct us428_ctls)
|
||||
|
||||
#define NRURBS 2
|
||||
|
||||
/* Default value used for nr of packs per urb.
|
||||
|
|
@ -55,7 +57,7 @@ struct usx2ydev {
|
|||
int stride;
|
||||
struct urb *in04_urb;
|
||||
void *in04_buf;
|
||||
char in04_last[24];
|
||||
char in04_last[USX2Y_IN04_SIZE];
|
||||
unsigned int in04_int_calls;
|
||||
struct snd_usx2y_urb_seq *us04;
|
||||
wait_queue_head_t in04_wait_queue;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user