Repository navigation
audio: multiband_drc: bound num_elems in IPC3 switch getter - #11278
Open
Shrusti-pk wants to merge 1 commit into
Open
Shrusti-pk wants to merge 1 commit into
Shrusti-pk wants to merge 1 commit into
Conversation
multiband_drc_cmd_get_value() fills cdata->chanv[j].value for j in [0, cdata->num_elems) and only afterwards looks at num_elems: the "num_elems should be 1" warning is emitted once the loop has already run, so it never prevents anything. num_elems is taken verbatim from the host SOF_IPC_COMP_GET_VALUE message. ipc_comp_value() does not validate it, and the IPC3 GET_VALUE path in module_adapter_cmd() passes 0 as fragment_size, so nothing bounds the loop. The reply buffer is ipc->comp_data, a single SOF_IPC_MSG_MAX_SIZE heap block (384 bytes for IPC3), and chanv starts 92 bytes into it, so only 36 elements fit. num_elems = 37 writes four bytes past the allocation and a large count walks well beyond it. Reject num_elems above SOF_IPC_MAX_CHANNELS before the loop, the same bound tdfb_cmd_get_value(), igo_nr_get_config(), rtnr_get_config() and volume_get_config() already apply. Requests of up to one element per channel behave as before. Signed-off-by: Shrushti P K <shrusthi@labs.digiscrypt.com>
Collaborator
|
Can one of the admins verify this patch?
|
PR 11278: test resultsRun date: 2026-10-08 15:24 UTC Tested commit: e23f138088d8e6168216e491f908f7374f069374 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
multiband_drc_cmd_get_value fills the reply array before it validates how many elements were asked for:
Verified under ASan with the getter built against the real ipc/control.h: num_elems 37 is a four byte heap-buffer-overflow write zero bytes past the 384 byte comp_data block, and with the bound in place num_elems of 1 and 8 behave exactly as before.