Skip to content

Commit b7579e8

Browse files
tiwaigregkh
authored andcommitted
ALSA: dummy: Check card index validity at probe
commit 02442d5 upstream. snd_dummy_probe() blindly trusts that the given devptr->id value is within the proper card index range. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range. Reported-by: syzbot+2fb5d1f7cc4c1f132bcc@syzkaller.appspotmail.com Closes: https://lore.kernel.org/6a73bd4d.01d0871a.3a0d52.0005.GAE@google.com Cc: <stable@vger.kernel.org> Link: https://patch.msgid.link/20260806100433.1287393-1-tiwai@suse.de Signed-off-by: Takashi Iwai <tiwai@suse.de> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 8ca3bd4 commit b7579e8

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

sound/drivers/dummy.c

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1025,6 +1025,12 @@ static int snd_dummy_probe(struct platform_device *devptr)
10251025
int idx, err;
10261026
int dev = devptr->id;
10271027

1028+
if (dev < 0 || dev >= SNDRV_CARDS) {
1029+
dev_warn(&devptr->dev,
1030+
"Invalid card index %d, using default 0\n", dev);
1031+
dev = 0;
1032+
}
1033+
10281034
err = snd_devm_card_new(&devptr->dev, index[dev], id[dev], THIS_MODULE,
10291035
sizeof(struct snd_dummy), &card);
10301036
if (err < 0)

0 commit comments

Comments
 (0)