]> exis.tech > repos - linux.git/commit
ALSA: usb-audio: caiaq: validate EP1 reply lengths
authorPengpeng Hou <pengpeng@iscas.ac.cn>
Sun, 5 Jul 2026 08:46:01 +0000 (16:46 +0800)
committerTakashi Iwai <tiwai@suse.de>
Sun, 5 Jul 2026 10:14:19 +0000 (12:14 +0200)
commitaba30af07d4fe499b50209801eba9da8a815522f
treeb9355957362cb1784365c4cd46d8da72d00da469
parent742a87fa54ad7123bff41bd1aa149fef6929a7af
ALSA: usb-audio: caiaq: validate EP1 reply lengths

usb_ep1_command_reply_dispatch() uses buf[0] as a command byte and then
reads command-specific fixed items from the same URB buffer. Several
paths use buf + 1, buf[1], buf[2], or buf + 3 without first proving that
urb->actual_length contains those bytes.

Add per-command length checks, use a payload length derived from the
bytes after the command byte for the control-state copy, and reject short
analog input payloads before the input helper reads fixed offsets from
the EP1 reply.

Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260705084601.56400-1-pengpeng@iscas.ac.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
sound/usb/caiaq/device.c
sound/usb/caiaq/input.c