linux/sound/usb
Baul Lee 4335e38778 ALSA: FCP: do not copy out an uninitialised init response
fcp_ioctl_init() allocates its response buffer with kmalloc() and copies
the whole buffer back to userspace:

	buf_size = init.step0_resp_size + init.step2_resp_size;

	void *resp __free(kfree) =
		kmalloc(buf_size, GFP_KERNEL);
	...
	if (copy_to_user(arg->resp, resp, buf_size))
		return -EFAULT;

Nothing clears the buffer, and the only writer of its leading
step0_resp_size bytes is the step-0 control transfer:

	err = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0),
		FCP_USB_REQ_STEP0,
		USB_RECIP_INTERFACE | USB_TYPE_CLASS | USB_DIR_IN,
		0, private->bInterfaceNumber,
		step0_resp, private->step0_resp_size);
	if (err < 0)
		return err;

usb_fill_control_urb() does not set URB_SHORT_NOT_OK, so a short or
zero-length data stage completes with status 0 and snd_usb_ctl_msg()
returns a small actual_length.  The only check is err < 0, so a short
transfer is accepted as success.

snd_usb_ctl_msg() copies the full size back unconditionally:

	buf = kmemdup(data, size, GFP_KERNEL);
	...
	memcpy(data, buf, size);

Bytes the device never wrote are therefore restored into resp unchanged
and copied to userspace.  step0_resp_size and step2_resp_size are each
validated only to 1..255, so the caller also picks the slab cache, from
kmalloc-8 up to kmalloc-512.

On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data
stage, s0 = s2 = 255:

  # init_on_alloc off, no spray
  step0 window [0,255): nonzero=94/255
  000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01
  010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff

  # same kernel, kmalloc-512 pre-seeded with an 8-byte tag
  step0 window [0,255): nonzero=219/255  tagbytes=232

  # identical run, init_on_alloc=1
  step0 window [0,255): nonzero=0/255  tagbytes=0

  # all three runs
  step2 window [255,510): device words matched=62/62

a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address
ffff8000805fc4a8.  The step-2 window is unaffected, so the disclosure is
exactly the step-0 region.

Zero the buffer, and require the step-0 transfer to deliver the full
step0_resp_size bytes so a short data stage is reported as an error.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

Fixes: 46757a3e7d ("ALSA: FCP: Add Focusrite Control Protocol driver")
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260805013804.38839-1-baul.lee@xbow.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
2026-08-05 09:37:35 +02:00
..
6fire ALSA: 6fire: bound the MIDI event length from the device 2026-08-05 09:32:42 +02:00
bcd2000 ALSA: bcd2000: clear the URB pointers on disconnect 2026-08-05 09:34:03 +02:00
caiaq ALSA: usb-audio: caiaq: validate EP1 reply lengths 2026-07-05 12:14:19 +02:00
hiface Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
line6 ALSA: usb-audio/line6: Add support for POD HD PRO 2026-04-21 10:07:45 +02:00
misc ALSA: ua101: Reject too-short USB descriptors 2026-05-19 08:08:41 +02:00
qcom ALSA: usb-audio: qcom: Free QMI handle 2026-06-25 13:56:21 +02:00
usx2y ALSA: usb-audio: um144mkii: use "var" keyword for data 2026-07-14 08:00:44 +02:00
card.c ALSA: usb-audio: Extend quirk_flags to 64bit 2026-07-29 09:47:22 +02:00
card.h ALSA: usb-audio: Optimize the copy of packet sizes for implicit fb handling 2026-02-16 15:13:35 +01:00
clock.c ALSA: usb-audio: add clock quirk for Motu 1248 2026-05-04 17:50:02 +02:00
clock.h ALSA: usb-audio: Constify audioformat pointer references 2020-11-23 15:15:36 +01:00
endpoint.c Merge branch 'for-linus' into for-next 2026-07-30 11:28:26 +02:00
endpoint.h ALSA: usb-audio: Remove unused function declaration 2023-08-01 16:56:57 +02:00
fcp.c ALSA: FCP: do not copy out an uninitialised init response 2026-08-05 09:37:35 +02:00
fcp.h ALSA: FCP: Add Focusrite Control Protocol driver 2025-01-18 12:00:38 +01:00
format.c ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES 2026-04-16 10:33:19 +02:00
format.h
helper.c ALSA: usb-audio: Export USB SND APIs for modules 2025-04-11 13:02:30 +02:00
helper.h ALSA: usb-audio: Support multiple control interfaces 2024-08-12 16:17:46 +02:00
implicit.c ALSA: usb-audio: Add implicit feedback quirk for RODE AI-1 2025-06-02 16:50:04 +02:00
implicit.h ALSA: usb-audio: Add new quirk FIXED_RATE for JBL Quantum810 Wireless 2022-12-22 09:13:54 +01:00
Kconfig ALSA:usb:qcom: add AUXILIARY_BUS to Kconfig dependencies 2026-03-18 12:36:39 +01:00
Makefile ALSA: usb-audio: qcom: Introduce QC USB SND offloading support 2025-04-11 13:02:32 +02:00
media.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
media.h
midi.c ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() 2026-07-26 09:49:26 +02:00
midi.h ALSA: usb-audio: Manage number of rawmidis globally 2023-05-23 12:11:00 +02:00
midi2.c ALSA: usb-audio: fix use-after-free in ump_to_endpoint() 2026-07-26 08:58:25 +02:00
midi2.h ALSA: usb-audio: USB MIDI 2.0 UMP support 2023-05-23 12:11:02 +02:00
mixer_maps.c ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision) 2026-07-28 18:30:43 +02:00
mixer_quirks.c Merge branch 'for-linus' into for-next 2026-07-30 11:28:26 +02:00
mixer_quirks.h ALSA: usb-audio: Drop CONFIG_PM ifdefs 2021-12-06 10:19:40 +01:00
mixer_s1810c.c ALSA: usb-audio: add Studio 1824 support 2026-03-09 13:00:57 +01:00
mixer_s1810c.h ALSA: usb-audio: Add support for Presonus Studio 1810c 2020-02-15 09:46:16 +01:00
mixer_scarlett.c ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() 2026-04-27 13:44:48 +02:00
mixer_scarlett.h ALSA: usb-audio: add mixer support for Focusrite Forte 2026-01-27 09:58:50 +01:00
mixer_scarlett2.c Revert "ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417" 2026-05-26 08:00:51 +02:00
mixer_scarlett2.h ALSA: scarlett2: Rename scarlett_gen2 to scarlett2 2023-10-27 11:22:59 +02:00
mixer_us16x08.c ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes 2026-04-27 13:44:49 +02:00
mixer_us16x08.h
mixer.c ALSA: usb-audio: Fix imbalance per-channel volume of sticky mixers 2026-07-06 10:22:43 +02:00
mixer.h ALSA: usb-audio: Add QUIRK_FLAG_MIXER_GET_CUR_BROKEN 2026-05-31 17:48:48 +02:00
pcm.c ALSA: usb-audio: Use the right limit for PCM OOB check 2026-01-21 09:22:12 +01:00
pcm.h ALSA: usb-audio: Export USB SND APIs for modules 2025-04-11 13:02:30 +02:00
power.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
power.h ALSA: usb-audio: Support multiple control interfaces 2024-08-12 16:17:46 +02:00
proc.c ALSA: usb-audio: Replace manual mutex/spinlock with guard() 2025-08-12 08:36:17 +02:00
proc.h
quirks-table.h ALSA: usb-audio: Add support for Pioneer DJ DJM-S11 2026-06-29 12:29:51 +02:00
quirks.c Merge branch 'for-linus' into for-next 2026-08-03 15:19:30 +02:00
quirks.h ALSA: usb-audio: Make some quirk-string helpers local 2026-07-29 09:47:22 +02:00
stream.c ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() 2026-04-28 08:14:21 +02:00
stream.h ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams 2026-04-28 08:13:50 +02:00
usbaudio.h ALSA: usb-audio: Extend quirk_flags to 64bit 2026-07-29 09:47:22 +02:00
validate.c ALSA: usb-audio: Use correct version for UAC3 header validation 2026-02-26 07:37:29 +01:00