In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: do not copy out an uninitialised init response fcp_ioctl_in
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS 벡터 정보 없음
상세 설명
In the Linux kernel, the following vulnerability has been resolved:
ALSA: FCP: do not copy out an uninitialised init response
fcp_ioctl_init() allocates its response buffer with kmalloc() and copies
the whole buffer back to userspace:
1buf_size = init.step0_resp_size + init.step2_resp_size; 2 3void *resp __free(kfree) = 4 kmalloc(buf_size, GFP_KERNEL); 5... 6if (copy_to_user(arg->resp, resp, buf_size)) 7 return -EFAULT;Nothing clears the buffer, and the only writer of its leading
step0_resp_size bytes is the step-0 control transfer:
1err = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0), 2 FCP_USB_REQ_STEP0, 3 USB_RECIP_INTERFACE | USB_TYPE_CLASS | USB_DIR_IN, 4 0, private->bInterfaceNumber, 5 step0_resp, private->step0_resp_size); 6if (err < 0) 7 return err;usb_fill_control_urb() does not set URB_SHORT_NOT_OK, so a short or
zero-length data stage completes with status 0 and snd_usb_ctl_msg()
returns a small actual_length. The only check is err < 0, so a short
transfer is accepted as success.
snd_usb_ctl_msg() copies the full size back unconditionally:
1buf = kmemdup(data, size, GFP_KERNEL); 2... 3memcpy(data, buf, size);Bytes the device never wrote are therefore restored into resp unchanged
and copied to userspace. step0_resp_size and step2_resp_size are each
validated only to 1..255, so the caller also picks the slab cache, from
kmalloc-8 up to kmalloc-512.
On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data
stage, s0 = s2 = 255:
init_on_alloc off, no spray
step0 window [0,255): nonzero=94/255
000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01
010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff
same kernel, kmalloc-512 pre-seeded with an 8-byte tag
step0 window [0,255): nonzero=219/255 tagbytes=232
identical run, init_on_alloc=1
step0 window [0,255): nonzero=0/255 tagbytes=0
all three runs
step2 window [255,510): device words matched=62/62
a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address
ffff8000805fc4a8. The step-2 window is unaffected, so the disclosure is
exactly the step-0 region.
Zero the buffer, and require the step-0 transfer to deliver the full
step0_resp_size bytes so a short data stage is reported as an error.
Discovered by XBOW, triaged by Baul Lee baul.lee@xbow.com
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.