From ea883f1e4c42039b2213ab5375dee6e02b05f29b Mon Sep 17 00:00:00 2001 From: Shrushti P K Date: Mon, 5 Oct 2026 21:47:42 +0530 Subject: [PATCH] audio: mfcc: validate config blob size before use mfcc_prepare() only checked that the configuration blob was non-empty before mfcc_setup() and the processing code dereferenced it as a struct sof_mfcc_config, over-reading adjacent heap for a short blob. Require the blob to cover the config struct. Signed-off-by: Shrushti P K --- src/audio/mfcc/mfcc.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/src/audio/mfcc/mfcc.c b/src/audio/mfcc/mfcc.c index 95daaecbce25..1be62be9cc8e 100644 --- a/src/audio/mfcc/mfcc.c +++ b/src/audio/mfcc/mfcc.c @@ -239,8 +239,11 @@ static int mfcc_prepare(struct processing_module *mod, cd->config = comp_get_data_blob(cd->model_handler, &data_size, NULL); - /* Initialize MFCC, max_frames is set to dev->frames + 4 */ - if (cd->config && data_size > 0) { + /* Initialize MFCC, max_frames is set to dev->frames + 4. The blob is + * dereferenced as a struct sof_mfcc_config below, in mfcc_setup() and + * in the processing code, so require it to be at least that large. + */ + if (cd->config && data_size >= sizeof(struct sof_mfcc_config)) { ret = mfcc_setup(mod, dev->frames + 4, audio_stream_get_rate(&sourceb->stream), audio_stream_get_channels(&sourceb->stream)); if (ret < 0) {