<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/stable/linux-stable.git/drivers/usb/gadget/function, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<id>http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/usb/gadget/function?h=master</id>
<link rel='self' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/usb/gadget/function?h=master'/>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/'/>
<updated>2026-10-01T05:12:43Z</updated>
<entry>
<title>usb: gadget: f_uac1_legacy: validate bRequest index in generic_{set,get}_cmd</title>
<updated>2026-10-01T05:12:43Z</updated>
<author>
<name>Liu Chao</name>
<email>liuc63@xiaopeng.com</email>
</author>
<published>2026-09-21T07:25:51Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=9062d50e75c24dc7911be05c9b1719b3b256af15'/>
<id>urn:sha1:9062d50e75c24dc7911be05c9b1719b3b256af15</id>
<content type='text'>
generic_set_cmd() and generic_get_cmd() use the low nibble of
ctrl-&gt;bRequest as an index into con-&gt;data[]:

    u8 cmd = (ctrl-&gt;bRequest &amp; 0x0F);  /* 0 .. 15 */
    ...
    con-&gt;data[cmd] = value;            /* OOB when cmd &gt;= 5 */

struct usb_audio_control (include/linux/usb/audio.h) declares data as
a 5-element array, so indices 5 through 15 write (or read) up to 44
bytes past the end of the array on the heap.

A malicious USB host can craft a class-specific SET_CUR / GET_CUR
request with an arbitrary bRequest value, triggering the out-of-bounds
access from an IRQ completion handler with no further preconditions.

Add an ARRAY_SIZE() guard to both functions.

Fixes: c47d7b09891a ("USB: audio: add USB audio class definitions")
Cc: stable &lt;stable@kernel.org&gt;
Reviewed-by: Weibin Liu &lt;liuwb@xiaopeng.com&gt;
Signed-off-by: Liu Chao &lt;liuc63@xiaopeng.com&gt;
Reviewed-by: Ivy Lopez &lt;skunkolee@gmail.com&gt;
Link: https://patch.msgid.link/20260921072551.3708191-1-liuc63@xiaopeng.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
</feed>
