Re: [PATCH v2] ALSA: pcmtest: handle multiple wraps in random capture fill

From: Takashi Iwai

Date: Sun Oct 04 2026 - 14:29:45 EST


On Sat, 03 Oct 2026 12:18:54 +0200,
tjdqudcks0424@xxxxxxxxx wrote:
>
> From: Sung Byeongchan <tjdqudcks0424@xxxxxxxxx>
>
> The random capture helpers assume that the data generated for one timer
> tick wraps the DMA ring at most once. However, b_rw describes 200 ms of
> audio because the timer runs at 5 Hz, so it can be several times larger
> than a small ring.
>
> For 48 kHz, S16_LE, four-channel capture with a 512-frame buffer, the DMA
> ring is 4096 bytes while one tick generates 76800 bytes. After filling the
> 4096-byte tail, the existing code issues a second 72704-byte write from the
> ring base, writing 68608 bytes beyond the ring. Both interleaved and
> non-interleaved capture are affected.
>
> KASAN reports the first write into the adjacent free page as a
> use-after-free in the random-byte generator. The underlying defect is an
> out-of-bounds write from the live DMA ring, not a stale DMA allocation.
>
> Split each random write repeatedly at the interleaved ring or per-channel
> block boundary. Keep the hardware-pointer update exactly once after the
> complete logical write.
>
> The issue reproduced on three of three clean boots. With this change, the
> same vulnerable geometry completed six times without a sanitizer finding.
> Boundary, pattern-fill, no-timer, open/close, and module-reload controls
> also completed normally.
>
> snd-pcmtest is a test driver, and selecting random fill requires an
> administrator-controlled module parameter. The written values come from the
> kernel random generator; no privilege escalation or attacker-controlled
> write primitive was demonstrated.
>
> Fixes: 315a3d57c64c ("ALSA: Implement the new Virtual PCM Test Driver")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: OpenAI Codex
> Signed-off-by: Sung Byeongchan <tjdqudcks0424@xxxxxxxxx>

Applied to for-next branch now. Thanks.


Takashi