Skip to content

audio: mfcc: validate config blob size before use - #11270

Open
Shrusti-pk wants to merge 1 commit into
thesofproject:mainfrom
Shrusti-pk:mfcc-blob-size
Open

Shrusti-pk wants to merge 1 commit into
thesofproject:mainfrom
Shrusti-pk:mfcc-blob-size

Conversation

@Shrusti-pk

Copy link
Copy Markdown

mfcc_prepare uses the config blob without checking it is long enough:

  • the blob length comes from the bytes control and is only tested for non-zero
  • mfcc_setup, the rest of prepare and the per-period processing code then read it as a 116-byte struct sof_mfcc_config, so a shorter blob is read past the end of its heap allocation
  • mfcc registers no blob validator, unlike drc, eq_iir, tdfb and multiband_drc, so nothing rejects a short blob at IPC time either

Required the blob to cover the config struct, as drc_prepare does since d859e5d; the shipped mfcc blobs are all exactly 116 bytes so valid topologies are unaffected.

mfcc_prepare() only checked that the configuration blob was non-empty
before mfcc_setup() and the processing code dereferenced it as a struct
sof_mfcc_config, over-reading adjacent heap for a short blob. Require
the blob to cover the config struct.

Signed-off-by: Shrushti P K <shrusthi@labs.digiscrypt.com>
@sofci

sofci commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Can one of the admins verify this patch?

reply test this please to run this test once

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants