[PATCH] ASoC: codec: sma1307: Fix memory corruption in sma1307_setting_loaded()

Dan Carpenter posted 1 patch 1 month ago
sound/soc/codecs/sma1307.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
[PATCH] ASoC: codec: sma1307: Fix memory corruption in sma1307_setting_loaded()
Posted by Dan Carpenter 1 month ago
The sma1307->set.header_size is how many integers are in the header
(there are 8 of them) but instead of allocating space of 8 integers
we allocate 8 bytes.  This leads to memory corruption when we copy data
it on the next line:

        memcpy(sma1307->set.header, data,
               sma1307->set.header_size * sizeof(int));

Also since we're immediately copying over the memory in ->set.header,
there is no need to zero it in the allocator.  Use devm_kmalloc_array()
to allocate the memory instead.

Fixes: 576c57e6b4c1 ("ASoC: sma1307: Add driver for Iron Device SMA1307")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
---
 sound/soc/codecs/sma1307.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/sound/soc/codecs/sma1307.c b/sound/soc/codecs/sma1307.c
index 6a601e7134ea..b683e676640d 100644
--- a/sound/soc/codecs/sma1307.c
+++ b/sound/soc/codecs/sma1307.c
@@ -1737,9 +1737,10 @@ static void sma1307_setting_loaded(struct sma1307_priv *sma1307, const char *fil
 	sma1307->set.checksum = data[sma1307->set.header_size - 2];
 	sma1307->set.num_mode = data[sma1307->set.header_size - 1];
 	num_mode = sma1307->set.num_mode;
-	sma1307->set.header = devm_kzalloc(sma1307->dev,
-					   sma1307->set.header_size,
-					   GFP_KERNEL);
+	sma1307->set.header = devm_kmalloc_array(sma1307->dev,
+						 sma1307->set.header_size,
+						 sizeof(int),
+						 GFP_KERNEL);
 	if (!sma1307->set.header) {
 		sma1307->set.status = false;
 		return;
-- 
2.47.2
Re: [PATCH] ASoC: codec: sma1307: Fix memory corruption in sma1307_setting_loaded()
Posted by Mark Brown 1 month ago
On Fri, 29 Aug 2025 15:57:34 +0300, Dan Carpenter wrote:
> The sma1307->set.header_size is how many integers are in the header
> (there are 8 of them) but instead of allocating space of 8 integers
> we allocate 8 bytes.  This leads to memory corruption when we copy data
> it on the next line:
> 
>         memcpy(sma1307->set.header, data,
>                sma1307->set.header_size * sizeof(int));
> 
> [...]

Applied to

   https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git for-next

Thanks!

[1/1] ASoC: codec: sma1307: Fix memory corruption in sma1307_setting_loaded()
      commit: 78338108b5a856dc98223a335f147846a8a18c51

All being well this means that it will be integrated into the linux-next
tree (usually sometime in the next 24 hours) and sent to Linus during
the next merge window (or sooner if it is a bug fix), however if
problems are discovered then the patch may be dropped or reverted.

You may get further e-mails resulting from automated or manual testing
and review of the tree, please engage with people reporting problems and
send followup patches addressing any issues that are reported if needed.

If any updates are required or you are submitting further changes they
should be sent as incremental updates against current git, existing
patches will not be replaced.

Please add any relevant lists and maintainers to the CCs when replying
to this mail.

Thanks,
Mark