From e23f138088d8e6168216e491f908f7374f069374 Mon Sep 17 00:00:00 2001 From: Shrushti P K Date: Wed, 7 Oct 2026 11:24:52 +0530 Subject: [PATCH] audio: multiband_drc: bound num_elems in IPC3 switch getter multiband_drc_cmd_get_value() fills cdata->chanv[j].value for j in [0, cdata->num_elems) and only afterwards looks at num_elems: the "num_elems should be 1" warning is emitted once the loop has already run, so it never prevents anything. num_elems is taken verbatim from the host SOF_IPC_COMP_GET_VALUE message. ipc_comp_value() does not validate it, and the IPC3 GET_VALUE path in module_adapter_cmd() passes 0 as fragment_size, so nothing bounds the loop. The reply buffer is ipc->comp_data, a single SOF_IPC_MSG_MAX_SIZE heap block (384 bytes for IPC3), and chanv starts 92 bytes into it, so only 36 elements fit. num_elems = 37 writes four bytes past the allocation and a large count walks well beyond it. Reject num_elems above SOF_IPC_MAX_CHANNELS before the loop, the same bound tdfb_cmd_get_value(), igo_nr_get_config(), rtnr_get_config() and volume_get_config() already apply. Requests of up to one element per channel behave as before. Signed-off-by: Shrushti P K --- src/audio/multiband_drc/multiband_drc_ipc3.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/audio/multiband_drc/multiband_drc_ipc3.c b/src/audio/multiband_drc/multiband_drc_ipc3.c index 04aa4fc33e40..1932cc18a8e4 100644 --- a/src/audio/multiband_drc/multiband_drc_ipc3.c +++ b/src/audio/multiband_drc/multiband_drc_ipc3.c @@ -69,6 +69,11 @@ static int multiband_drc_cmd_get_value(struct processing_module *mod, switch (cdata->cmd) { case SOF_CTRL_CMD_SWITCH: comp_dbg(dev, "SOF_CTRL_CMD_SWITCH"); + if (cdata->num_elems > SOF_IPC_MAX_CHANNELS) { + comp_err(dev, "num_elems %u out of range", cdata->num_elems); + return -EINVAL; + } + for (j = 0; j < cdata->num_elems; j++) cdata->chanv[j].value = cd->process_enabled; if (cdata->num_elems == 1)