PT-2026-90100 · Linux · Linux
CVE-2026-80970
·
Published
2026-09-11
·
Updated
2026-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: FCP: do not copy out an uninitialised init response
fcp ioctl init() allocates its response buffer with kmalloc() and copies
the whole buffer back to userspace:
buf size = init.step0 resp size + init.step2 resp size;
void *resp free(kfree) =
kmalloc(buf size, GFP KERNEL);
...
if (copy to user(arg->resp, resp, buf size))
return -EFAULT;Nothing clears the buffer, and the only writer of its leading
step0 resp size bytes is the step-0 control transfer:
err = snd usb ctl msg(dev, usb rcvctrlpipe(dev, 0),
FCP USB REQ STEP0,
USB RECIP INTERFACE | USB TYPE CLASS | USB DIR IN,
0, private->bInterfaceNumber,
step0 resp, private->step0 resp size);
if (err < 0)
return err;usb fill control urb() does not set URB SHORT NOT OK, so a short or
zero-length data stage completes with status 0 and snd usb ctl msg()
returns a small actual length. The only check is err < 0, so a short
transfer is accepted as success.
snd usb ctl msg() copies the full size back unconditionally:
buf = kmemdup(data, size, GFP KERNEL);
...
memcpy(data, buf, size);Bytes the device never wrote are therefore restored into resp unchanged
and copied to userspace. step0 resp size and step2 resp size are each
validated only to 1..255, so the caller also picks the slab cache, from
kmalloc-8 up to kmalloc-512.
On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data
stage, s0 = s2 = 255:
init on alloc off, no spray
step0 window [0,255): nonzero=94/255
000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01
010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff
same kernel, kmalloc-512 pre-seeded with an 8-byte tag
step0 window [0,255): nonzero=219/255 tagbytes=232
identical run, init on alloc=1
step0 window [0,255): nonzero=0/255 tagbytes=0
all three runs
step2 window [255,510): device words matched=62/62
a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address
ffff8000805fc4a8. The step-2 window is unaffected, so the disclosure is
exactly the step-0 region.
Zero the buffer, and require the step-0 transfer to deliver the full
step0 resp size bytes so a short data stage is reported as an error.
Discovered by XBOW, triaged by Baul Lee baul.lee@xbow.com
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux