]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
ALSA: FCP: Fix NULL pointer dereference in interface lookup
authorJiaming Zhang <r772577952@gmail.com>
Thu, 25 Jun 2026 13:49:33 +0000 (21:49 +0800)
committerTakashi Iwai <tiwai@suse.de>
Fri, 26 Jun 2026 05:46:59 +0000 (07:46 +0200)
commite1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c
tree29a9b9af113b578b625a115338d76d2cf318e8f4
parent9dbbe81962b973fe71592ad8615d1e6cd28451bf
ALSA: FCP: Fix NULL pointer dereference in interface lookup

A malformed USB device can provide a vendor-specific interface without
any endpoint descriptors. fcp_find_fc_interface() currently selects the
first vendor-specific interface and reads endpoint 0 from it, without
checking whether the interface actually has any endpoints.

When bNumEndpoints is zero, no endpoint array is allocated for the parsed
alternate setting, so get_endpoint(..., 0) yields an invalid endpoint
descriptor pointer. Dereferencing it through usb_endpoint_num() then
triggers a NULL pointer dereference.

Skip vendor-specific interfaces that do not have any endpoints.

Fixes: 46757a3e7d50 ("ALSA: FCP: Add Focusrite Control Protocol driver")
Reported-by: Jiaming Zhang <r772577952@gmail.com>
Closes: https://lore.kernel.org/lkml/CANypQFb1EHj0xX8bA1WxSOSK-5xca6ZNKzOQcp12=s=puY7VFw@mail.gmail.com/
Signed-off-by: Jiaming Zhang <r772577952@gmail.com>
Link: https://patch.msgid.link/20260625134933.425785-1-r772577952@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
sound/usb/fcp.c