{"id":"CVE-2026-74640","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74640","summary":"ALSA: FCP: fix OOB write in fcp_meter_ctl_get()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: FCP: fix OOB write in fcp_meter_ctl_get()\n\nfcp_ioctl_set_meter_map() bounds the user-supplied Level Meter map size\nby the driver's own limit of 255\n\n\tif (map.map_size < 1 || map.map_size > 255 ||\n\t    map.meter_slots < 1 || map.meter_slots > 255)\n\t\treturn -EINVAL;\n\nand passes it to fcp_add_new_ctl() as the control's channel count, where\nit is stored as elem->channels.\n\nEvery control read writes into struct snd_ctl_elem_value, whose integer\narray is declared long value[128], so the limit is 128, not 255.\nfcp_meter_ctl_get() stores one 64-bit word per channel into that array\nwith no bound of its own:\n\n\tfor (i = 0; i < elem->channels; i++) {\n\t\tint idx = private->meter_level_map[i];\n\t\tint value = idx < 0 ? 0 : le32_to_cpu(resp[idx]);\n\n\t\tucontrol->value.integer.value[i] = value;\n\t}\n\nsnd_ctl_elem_read_user() serves that object from\nmemdup_user(_control, sizeof(*control)), 1224 bytes on LP64 out of\nkmalloc-2048.  offsetof(struct snd_ctl_elem_value, value) is 72, so\nelement i is written at byte 72 + 8 * i and element 144 already lands\npast the allocation.  At map_size 255 the last store ends at byte 2112,\n888 bytes past the object and 64 bytes into the adjacent slab object.\nThe stored words come from the device and meter_level_map[] selects\nwhich word lands in which slot, so extent and contents are both\ncontrolled.\n\nThe core does not catch this.  snd_ctl_check_elem_info() is reached only\nfrom __snd_ctl_elem_info(), which snd_ctl_elem_read() calls under\nCONFIG_SND_CTL_DEBUG; without that option snd_ctl_skip_validation() is a\ncompile-time true.  __snd_ctl_add_replace() validates kcontrol->count and\nnever inspects elem->channels.\n\nInstalling an oversized map needs CAP_SYS_RAWIO, but the control outlives\nthe hwdep descriptor that created it, so the out-of-bounds stores are\nissued by any process able to read controls on /dev/snd/controlC0.\n\nKASAN on 7.2.0-rc5 (arm64), triggered by an unprivileged control read:\n\n  BUG: KASAN: slab-out-of-bounds in fcp_meter_ctl_get\n  Write of size 8 at addr ffff000017af04c8 by task fcp_trigger/185\n   __asan_store8\n   fcp_meter_ctl_get\n   snd_ctl_elem_read\n   snd_ctl_ioctl\n  Allocated by task 185:\n   memdup_user\n   snd_ctl_ioctl\n  The buggy address is located 0 bytes to the right of\n   allocated 1224-byte region [ffff000017af0000, ffff000017af04c8)\n\nBound the map size by the ABI limit rather than by 255, and bound the\nstore loop at the sink so it cannot run past the value array whatever\nelem->channels holds.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","published":"2026-08-22T15:32:18.957Z","modified":"2026-08-24T11:47:18.929830013Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.18.45"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/620f1e52a46f604635efd0fb78138afd6a513b5d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bb30e35c36ed00f24fa39aded811f64230a913b0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bb61dc2ae59026f76db26e1909746908bc5b6f31"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74640.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74640"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T11:47:18.929830013Z"}}