ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf

The in04_last array in struct usx2ydev is declared as char[24], but
in04_buf is allocated as sizeof(struct us428_ctls) which is 21 bytes.
In i_usx2y_in04_int(), when ctl_snapshot_last == -2 (initialization
path):

    memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));

This copies 24 bytes from a 21-byte slab allocation, reading 3 bytes
past the end of the source object.

Introduce a USX2Y_IN04_SIZE constant defined as sizeof(struct
us428_ctls) and use it consistently for the in04_last array, the
in04_buf allocation, the URB transfer length, and the comparison loop,
replacing the bare 24 and 21 literals throughout.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Link: https://patch.msgid.link/20260904205826.4071119-1-tristmd@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
This commit is contained in:
Tristan Madani 2026-09-04 20:58:25 +00:00 committed by Takashi Iwai
parent b26a7a80e6
commit 861111a147
2 changed files with 6 additions and 4 deletions

View File

@ -196,7 +196,7 @@ static void i_usx2y_in04_int(struct urb *urb)
memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));
us428ctls->ctl_snapshot_last = -1;
} else {
for (i = 0; i < 21; i++) {
for (i = 0; i < USX2Y_IN04_SIZE; i++) {
if (usx2y->in04_last[i] != ((char *)usx2y->in04_buf)[i]) {
if (diff < 0)
diff = i;
@ -305,7 +305,7 @@ int usx2y_in04_init(struct usx2ydev *usx2y)
goto error;
}
usx2y->in04_buf = kmalloc(21, GFP_KERNEL);
usx2y->in04_buf = kmalloc(USX2Y_IN04_SIZE, GFP_KERNEL);
if (!usx2y->in04_buf) {
err = -ENOMEM;
goto error;
@ -313,7 +313,7 @@ int usx2y_in04_init(struct usx2ydev *usx2y)
init_waitqueue_head(&usx2y->in04_wait_queue);
usb_fill_int_urb(usx2y->in04_urb, usx2y->dev, usb_rcvintpipe(usx2y->dev, 0x4),
usx2y->in04_buf, 21,
usx2y->in04_buf, USX2Y_IN04_SIZE,
i_usx2y_in04_int, usx2y,
10);
if (usb_urb_ep_type_check(usx2y->in04_urb)) {

View File

@ -5,6 +5,8 @@
#include "../midi.h"
#include "usbus428ctldefs.h"
#define USX2Y_IN04_SIZE sizeof(struct us428_ctls)
#define NRURBS 2
/* Default value used for nr of packs per urb.
@ -55,7 +57,7 @@ struct usx2ydev {
int stride;
struct urb *in04_urb;
void *in04_buf;
char in04_last[24];
char in04_last[USX2Y_IN04_SIZE];
unsigned int in04_int_calls;
struct snd_usx2y_urb_seq *us04;
wait_queue_head_t in04_wait_queue;