[PATCH 09/11] ALSA: line6: Reject too small max packet sizes
From: Takashi Iwai
Date: Thu Oct 08 2026 - 15:27:34 EST
Although the LINE6 driver has a sanity check for the given max packet
sizes, it still has an implicit requirement of the minimal size being
bytes-per-frame; e.g. the impulse test signal assuming the fixed size,
and when a too small size is specified by a malformed USB descriptor,
this may lead to an OOB access.
Change the sanity check conditions to reject too small max packet
sizes for avoiding the scenario above.
Fixes: 3450121997ce ("ALSA: line6: Fix write on zero-sized buffer")
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Signed-off-by: Takashi Iwai <tiwai@xxxxxxx>
---
sound/usb/line6/pcm.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/sound/usb/line6/pcm.c b/sound/usb/line6/pcm.c
index 2932eaf157f4..998869dc4613 100644
--- a/sound/usb/line6/pcm.c
+++ b/sound/usb/line6/pcm.c
@@ -554,7 +554,11 @@ int line6_init_pcm(struct usb_line6 *line6,
line6pcm->max_packet_size_out =
usb_maxpacket(line6->usbdev,
usb_sndisocpipe(line6->usbdev, ep_write));
- if (!line6pcm->max_packet_size_in || !line6pcm->max_packet_size_out) {
+ /* reject max packet sizes smaller than bytes-per-frame;
+ * (the magic number 6 is taken from the playback case)
+ */
+ if (line6pcm->max_packet_size_in < 6 ||
+ line6pcm->max_packet_size_out < 6) {
dev_err(line6pcm->line6->ifcdev,
"cannot get proper max packet size\n");
return -EINVAL;
--
2.55.0