lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20251204052201.16286-3-hariconscious@gmail.com>
Date: Thu,  4 Dec 2025 10:52:03 +0530
From: hariconscious@...il.com
To: perex@...ex.cz,
	tiwai@...e.com,
	cristian.ciocaltea@...labora.com,
	cryolitia@...ontech.com,
	franta-linux@...ntovo.cz
Cc: khalid@...nel.org,
	shuah@...nel.org,
	david.hunter.linux@...il.com,
	linux-sound@...r.kernel.org,
	linux-kernel@...r.kernel.org,
	HariKrishna Sagala <hariconscious@...il.com>,
	Takashi Iwai <tiwai@...e.de>
Subject: [PATCH v2] ALSA: usb-audio: Initialize status1 to fix uninitialized symbol errors

From: HariKrishna Sagala <hariconscious@...il.com>

Initialize 'status1' with a default value to resolve the static analysis
smatch reported error "uninitialized symbol 'status1'".
The 'status1' variable is used to create a buff using "kmemdup".
So, ensure to initialize the value before it is read.

Suggested-by: Takashi Iwai <tiwai@...e.de>
Signed-off-by: HariKrishna Sagala <hariconscious@...il.com>
---
This patch fixes the below smatch reported errors.
sound/usb/mixer_quirks.c:2462 snd_rme_rate_get() error: uninitialized symbol 'status1'.
sound/usb/mixer_quirks.c:2467 snd_rme_rate_get() error: uninitialized symbol 'status1'.
sound/usb/mixer_quirks.c:2472 snd_rme_rate_get() error: uninitialized symbol 'status1'.
sound/usb/mixer_quirks.c:2495 snd_rme_sync_state_get() error: uninitialized symbol 'status1'.
sound/usb/mixer_quirks.c:2501 snd_rme_sync_state_get() error: uninitialized symbol 'status1'.
sound/usb/mixer_quirks.c:2522 snd_rme_spdif_if_get() error: uninitialized symbol 'status1'.
sound/usb/mixer_quirks.c:2535 snd_rme_spdif_format_get() error: uninitialized symbol 'status1'.
sound/usb/mixer_quirks.c:2548 snd_rme_sync_source_get() error: uninitialized symbol 'status1'.

The below is the flow of 'status1' it is used before initialization.

snd_rme_rate_get -> status1 is uninitialized and passed
        snd_rme_get_status1 -> passed as is
                snd_rme_read_value -> passed as is
                        snd_usb_ctl_msg -> created buf from status1 using kmemdup
                                usb_control_msg -> sent buf for reading/writing

Description of "usb_control_msg", states as
" * @data: pointer to the data to send"

Later from Usb control request, dst buf is copied to src buf but usb
control msg request is made before initialization.

All the above warning reported functions, call snd_rme_get_status1().

v2:
Corrected as suggested by Takashi Iwai to silence the warnings
from callee side as it can reduce number of changes.

v1:
https://lore.kernel.org/all/20251203083319.58555-2-hariconscious@gmail.com/

Thank you.

 sound/usb/mixer_quirks.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/usb/mixer_quirks.c b/sound/usb/mixer_quirks.c
index 828af3095b86..f3e15825bc02 100644
--- a/sound/usb/mixer_quirks.c
+++ b/sound/usb/mixer_quirks.c
@@ -2440,6 +2440,7 @@ static int snd_rme_get_status1(struct snd_kcontrol *kcontrol,
 	struct usb_mixer_elem_list *list = snd_kcontrol_chip(kcontrol);
 	struct snd_usb_audio *chip = list->mixer->chip;
 
+	*status1 = 0;
 	CLASS(snd_usb_lock, pm)(chip);
 	if (pm.err < 0)
 		return pm.err;

base-commit: 4a26e7032d7d57c998598c08a034872d6f0d3945
-- 
2.43.0


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ