Skip to content

audio: mfcc: validate config blob size before use - #11270

Merged
lgirdwood merged 1 commit into
thesofproject:mainfrom
Shrusti-pk:mfcc-blob-size
Oct 9, 2026
Merged

lgirdwood merged 1 commit into
thesofproject:mainfrom
Shrusti-pk:mfcc-blob-size

Conversation

@Shrusti-pk

Copy link
Copy Markdown
Contributor

mfcc_prepare uses the config blob without checking it is long enough:

  • the blob length comes from the bytes control and is only tested for non-zero
  • mfcc_setup, the rest of prepare and the per-period processing code then read it as a 116-byte struct sof_mfcc_config, so a shorter blob is read past the end of its heap allocation
  • mfcc registers no blob validator, unlike drc, eq_iir, tdfb and multiband_drc, so nothing rejects a short blob at IPC time either

Required the blob to cover the config struct, as drc_prepare does since d859e5d; the shipped mfcc blobs are all exactly 116 bytes so valid topologies are unaffected.

mfcc_prepare() only checked that the configuration blob was non-empty
before mfcc_setup() and the processing code dereferenced it as a struct
sof_mfcc_config, over-reading adjacent heap for a short blob. Require
the blob to cover the config struct.

Signed-off-by: Shrushti P K <shrusthi@labs.digiscrypt.com>
@sofci

sofci commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Can one of the admins verify this patch?

reply test this please to run this test once

@kv2019i kv2019i left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @Shrusti-pk for the patch!

@kv2019i
kv2019i requested a review from singalsu October 8, 2026 06:51
@abonislawski

Copy link
Copy Markdown
Member

CI triggered

@intel-sofci

intel-sofci commented Oct 8, 2026 •

Copy link
Copy Markdown

PR 11270: test results

Run date: 2026-10-09 08:13 UTC

Tested commit: ea883f1e4c42039b2213ab5375dee6e02b05f29b

mtl pass rate lnl pass rate ptl pass rate wcl pass rate nvl pass rate

@lgirdwood
lgirdwood merged commit 62325d8 into thesofproject:main Oct 9, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants