Re: [PATCH] ALSA: usx2y: bound the hwdep mmap fault offset
From: Takashi Iwai
Date: Wed Aug 05 2026 - 03:46:29 EST
On Wed, 05 Aug 2026 03:34:45 +0200,
Baul Lee wrote:
>
> snd_us428ctls_vm_fault() turns the faulting page offset into a kernel
> address with no bound of any kind:
>
> offset = vmf->pgoff << PAGE_SHIFT;
> vaddr = (char *)(...)->us428ctls_sharedmem + offset;
> page = virt_to_page(vaddr);
> get_page(page);
> vmf->page = page;
>
> return 0;
>
> snd_us428ctls_mmap() checks only the length of the mapping, never the
> offset, and us428ctls_sharedmem is a single page from
> alloc_pages_exact(). For a character device file_mmap_size_max()
> returns ULONG_MAX, so the mm layer imposes no ceiling either. Every page
> offset above zero resolves to a struct page outside the object, and the
> handler installs it into the caller's address space read-write; the vma
> is not marked read-only.
>
> The caller picks the page frame with a single mmap() argument and gets
> read-write access to a page of kernel memory it does not own; an offset
> that lands in an unpopulated vmemmap region oopses instead.
>
> A process that can open the hwdep node of an attached US-X2Y reaches
> this after loading the FPGA image through the same node; no capability
> check is involved.
>
> On 7.2.0-rc5 (arm64), mmap() with a large offset:
>
> Unable to handle kernel paging request at virtual address fffffdffc45d5ac8
> pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]
> Call trace:
> snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]
> __do_fault
> __handle_mm_fault
> handle_mm_fault
> el0_da
>
> Reject any offset outside the shared region. The pcm hwdep handler in
> usx2yhwdeppcm.c computes its address the same way and needs the same
> bound.
>
> Discovered by XBOW, triaged by Baul Lee <baul.lee@xxxxxxxx>
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Reported-by: Federico Kirschbaum <federico.kirschbaum@xxxxxxxx>
> Reported-by: Baul Lee <baul.lee@xxxxxxxx>
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Baul Lee <baul.lee@xxxxxxxx>
Applied now. Thanks.
Takashi