Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #90313 > unrolled thread

Bug#1121535: linux-image-6.17.8+deb14-amd64: array-index-out-of-bounds trace during boot (...ctamixer.c:347:48)

Started bywaxhead <waxhead@dirtcellar.net>
First post2025-11-28 00:10 +0100
Last post2026-02-03 22:40 +0100
Articles 6 — 4 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1121535: linux-image-6.17.8+deb14-amd64: array-index-out-of-bounds trace during boot (...ctamixer.c:347:48) waxhead <waxhead@dirtcellar.net> - 2025-11-28 00:10 +0100
    Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48 Salvatore Bonaccorso <carnil@debian.org> - 2025-11-29 09:10 +0100
      Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48 Karsten Hohmeier <linux@hohmatik.de> - 2025-12-26 22:40 +0100
    Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48 Karsten Hohmeier <linux@hohmatik.de> - 2026-01-10 11:50 +0100
    Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48 Karsten Hohmeier <linux@hohmatik.de> - 2026-01-18 20:00 +0100
    Bug#1121535: marked as done (linux-image-6.17.8+deb14-amd64:  array-index-out-of-bounds trace during boot (...ctamixer.c:347:48)) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2026-02-03 22:40 +0100

#90313 — Bug#1121535: linux-image-6.17.8+deb14-amd64: array-index-out-of-bounds trace during boot (...ctamixer.c:347:48)

Fromwaxhead <waxhead@dirtcellar.net>
Date2025-11-28 00:10 +0100
SubjectBug#1121535: linux-image-6.17.8+deb14-amd64: array-index-out-of-bounds trace during boot (...ctamixer.c:347:48)
Message-ID<LVThD-gg3t-5@gated-at.bofh.it>
Package: src:linux
Version: 6.17.8-1
Severity: normal
X-Debbugs-Cc: waxhead@dirtcellar.net

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
Some kernel updates ago (can't remember for how long back) just booting up my system has caused consistent "crash traces" in the kernel log.

   * What exactly did you do (or not do) that was effective (or
     ineffective)?
I have not tried anything. I am not familiar with kernel development. The system boots and (seems to) work just fine.

   * What was the outcome of this action?
This is the kernel trace:

 ------------[ cut here ]------------
Nov 27 23:46:53 main kernel: UBSAN: array-index-out-of-bounds in /build/reproducible-path/linux-6.17.8/sound/pci/ctxfi/ctamixer.c:347:48
Nov 27 23:46:53 main kernel: index 8 is out of range for type 'unsigned char [8]'
Nov 27 23:46:53 main kernel: CPU: 4 UID: 0 PID: 468 Comm: (udev-worker) Not tainted 6.17.8+deb14-amd64 #1 PREEMPT(lazy)  Debian 6.17.8-1 
Nov 27 23:46:53 main kernel: Hardware name: FUJITSU /D3446-S2, BIOS V5.0.0.12 R1.26.0 for D3446-S2x                    02/11/2020
Nov 27 23:46:53 main kernel: Call Trace:
Nov 27 23:46:53 main kernel:  <TASK>
Nov 27 23:46:53 main kernel:  dump_stack_lvl+0x5d/0x80
Nov 27 23:46:53 main kernel:  ? __pfx_amixer_set_x+0x10/0x10 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  ubsan_epilogue+0x5/0x2b
Nov 27 23:46:53 main kernel:  __ubsan_handle_out_of_bounds.cold+0x54/0x59
Nov 27 23:46:53 main kernel:  sum_output_slot+0x44/0x70 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  amixer_set_input+0x4b/0x80 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  amixer_setup+0x1b/0x50 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  ct_mixer_create+0x193/0x570 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  ct_atc_create+0x3cb/0x530 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  ct_card_probe+0x104/0x2c0 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  local_pci_probe+0x3f/0x90
Nov 27 23:46:53 main kernel:  pci_device_probe+0xda/0x2b0
Nov 27 23:46:53 main kernel:  ? sysfs_do_create_link_sd+0x6d/0xd0
Nov 27 23:46:53 main kernel:  really_probe+0xdb/0x340
Nov 27 23:46:53 main kernel:  ? pm_runtime_barrier+0x55/0x90
Nov 27 23:46:53 main kernel:  __driver_probe_device+0x78/0x140
Nov 27 23:46:53 main kernel:  driver_probe_device+0x1f/0xa0
Nov 27 23:46:53 main kernel:  ? __pfx___driver_attach+0x10/0x10
Nov 27 23:46:53 main kernel:  __driver_attach+0xcb/0x1e0
Nov 27 23:46:53 main kernel:  bus_for_each_dev+0x82/0xd0
Nov 27 23:46:53 main kernel:  bus_add_driver+0x10b/0x1f0
Nov 27 23:46:53 main kernel:  ? __pfx_ct_driver_init+0x10/0x10 [snd_ctxfi]
Nov 27 23:46:53 main kernel:  driver_register+0x75/0xe0
Nov 27 23:46:53 main kernel:  do_one_initcall+0x58/0x300
Nov 27 23:46:53 main kernel:  do_init_module+0x62/0x250
Nov 27 23:46:53 main kernel:  ? init_module_from_file+0x8a/0xe0
Nov 27 23:46:53 main kernel:  init_module_from_file+0x8a/0xe0
Nov 27 23:46:53 main kernel:  idempotent_init_module+0x114/0x310
Nov 27 23:46:53 main kernel:  __x64_sys_finit_module+0x6d/0xd0
Nov 27 23:46:53 main kernel:  ? syscall_trace_enter+0x8d/0x1d0
Nov 27 23:46:53 main kernel:  do_syscall_64+0x82/0x320
Nov 27 23:46:53 main kernel:  ? restore_fpregs_from_fpstate+0x46/0xa0
Nov 27 23:46:53 main kernel:  ? switch_fpu_return+0x5b/0xe0
Nov 27 23:46:53 main kernel:  ? do_syscall_64+0x200/0x320
Nov 27 23:46:53 main kernel:  ? exc_page_fault+0x74/0x180
Nov 27 23:46:53 main kernel:  entry_SYSCALL_64_after_hwframe+0x76/0x7e
Nov 27 23:46:53 main kernel: RIP: 0033:0x7f77238f3779
Nov 27 23:46:53 main kernel: Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 4f 86 0d 00 f7 d8 64 89 01 48
Nov 27 23:46:53 main kernel: RSP: 002b:00007ffc398103f8 EFLAGS: 00000246 ORIG_RAX: 0000000000000139
Nov 27 23:46:53 main kernel: RAX: ffffffffffffffda RBX: 000055e0eb622480 RCX: 00007f77238f3779
Nov 27 23:46:53 main kernel: RDX: 0000000000000004 RSI: 00007f77239f744d RDI: 000000000000001b
Nov 27 23:46:53 main kernel: RBP: 0000000000000004 R08: 0000000000000000 R09: 00007f7723ef6280
Nov 27 23:46:53 main kernel: R10: 0000000000000000 R11: 0000000000000246 R12: 00007f77239f744d
Nov 27 23:46:53 main kernel: R13: 0000000000020000 R14: 000055e0eb61e630 R15: 0000000000000000
Nov 27 23:46:53 main kernel:  </TASK>
Nov 27 23:46:53 main kernel: ---[ end trace ]---

   * What outcome did you expect instead?
I did not expect to see any "crash trace".


*** End of the template - remove these template lines ***


-- Package-specific info:
** Version:
Linux version 6.17.8+deb14-amd64 (debian-kernel@lists.debian.org) (x86_64-linux-gnu-gcc-15 (Debian 15.2.0-8) 15.2.0, GNU ld (GNU Binutils for Debian) 2.45) #1 SMP PREEMPT_DYNAMIC Debian 6.17.8-1 (2025-11-15)

** Command line:
BOOT_IMAGE=/@rootfs/boot/vmlinuz-6.17.8+deb14-amd64 root=UUID=d3a1dc89-4bed-4167-9bd0-80c504180cc4 ro rootflags=subvol=@rootfs quiet

** Tainted: POE (12289)
 * proprietary module was loaded
 * externally-built ("out-of-tree") module was loaded
 * unsigned module was loaded

** Kernel log:
Unable to read kernel log; any relevant messages should be attached

** Model information
sys_vendor: FUJITSU
product_name: 
product_version: 
chassis_vendor: FUJITSU
chassis_version: 
bios_vendor: FUJITSU // American Megatrends Inc.
bios_version: V5.0.0.12 R1.26.0 for D3446-S2x                   
board_vendor: FUJITSU
board_name: D3446-S2
board_version: S26361-D3446-S2            

** Configuration for modprobe:
blacklist microcode
blacklist arkfb
blacklist aty128fb
blacklist atyfb
blacklist radeonfb
blacklist cirrusfb
blacklist cyber2000fb
blacklist kyrofb
blacklist matroxfb_base
blacklist mb862xxfb
blacklist neofb
blacklist pm2fb
blacklist pm3fb
blacklist s3fb
blacklist savagefb
blacklist sisfb
blacklist tdfxfb
blacklist tridentfb
blacklist vt8623fb
blacklist microcode
blacklist nouveau
install nvidia modprobe -i nvidia-current $CMDLINE_OPTS
install nvidia_modeset modprobe nvidia ; modprobe -i nvidia-current-modeset $CMDLINE_OPTS
install nvidia_drm modprobe nvidia-modeset ; modprobe -i nvidia-current-drm $CMDLINE_OPTS
install nvidia_uvm modprobe nvidia ; modprobe -i nvidia-current-uvm $CMDLINE_OPTS
install nvidia_peermem modprobe nvidia ; modprobe -i nvidia-current-peermem $CMDLINE_OPTS
remove nvidia modprobe -r -i nvidia-drm nvidia-modeset nvidia-peermem nvidia-uvm nvidia
remove nvidia_modeset modprobe -r -i nvidia-drm nvidia-modeset
options snd_pcsp index=-2
options cx88_alsa index=-2
options snd_atiixp_modem index=-2
options snd_intel8x0m index=-2
options snd_via82xx_modem index=-2
options bonding max_bonds=0
options dummy numdummies=0
options ifb numifbs=0

** Loaded modules:
snd_seq_dummy
snd_hrtimer
snd_seq
snd_seq_device
rpcsec_gss_krb5
auth_rpcgss
nfsv4
dns_resolver
nfs
lockd
grace
netfs
xt_CHECKSUM
xt_MASQUERADE
xt_conntrack
ipt_REJECT
nf_reject_ipv4
xt_tcpudp
nft_compat
x_tables
nft_chain_nat
nf_nat
nf_conntrack
nf_defrag_ipv6
nf_defrag_ipv4
nf_tables
bridge
stp
llc
qrtr
cfg80211
rfkill
nvidia_drm(POE)
drm_ttm_helper
ttm
drm_client_lib
drm_kms_helper
nvidia_modeset(POE)
sunrpc
binfmt_misc
nvidia(POE)
nls_ascii
nls_cp437
vfat
xpad
fat
intel_rapl_msr
intel_rapl_common
intel_uncore_frequency
intel_uncore_frequency_common
intel_pmc_core_pltdrv
intel_pmc_core
pmt_telemetry
pmt_discovery
pmt_class
intel_pmc_ssram_telemetry
intel_vsec
x86_pkg_temp_thermal
intel_powerclamp
joydev
hid_logitech
ff_memless
coretemp
hid_generic
ext4
kvm_intel
mei_wdt
pl2303
usbhid
crc16
mbcache
mei_pxp
jbd2
usbserial
hid
mei_hdcp
snd_hda_codec_alc662
kvm
snd_hda_codec_realtek_lib
snd_hda_codec_generic
snd_hda_codec_nvhdmi
snd_hda_codec_hdmi
snd_soc_avs
irqbypass
ghash_clmulni_intel
snd_soc_hda_codec
snd_hda_intel
snd_hda_ext_core
aesni_intel
snd_hda_codec
rapl
intel_cstate
snd_hda_core
intel_uncore
snd_intel_dspcfg
ee1004
snd_soc_core
pcspkr
snd_intel_sdw_acpi
snd_compress
snd_ctxfi
snd_pcm_dmaengine
snd_hwdep
snd_pcm
snd_timer
snd
soundcore
mei_me
mei
intel_pch_thermal
acpi_pad
sg
evdev
dm_mod
drm
ppdev
lp
parport_pc
i2c_dev
parport
msr
efi_pstore
configfs
nfnetlink
efivarfs
autofs4
crc32c_cryptoapi
btrfs
blake2b_generic
xor
raid6_pq
sd_mod
ahci
libahci
xhci_pci
libata
xhci_hcd
igb
wdat_wdt
psmouse
video
usbcore
i2c_algo_bit
watchdog
e1000e
scsi_mod
serio_raw
dca
i2c_i801
wmi
button
i2c_smbus
scsi_common
usb_common

** PCI devices:
00:00.0 Host bridge [0600]: Intel Corporation Xeon E3-1200 v6/7th Gen Core Processor Host Bridge/DRAM Registers [8086:591f] (rev 05)
	Subsystem: Fujitsu Technology Solutions Device [1734:121c]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort+ >SERR- <PERR- INTx-
	Latency: 0
	IOMMU group: 0
	Capabilities: <access denied>
	Kernel driver in use: skl_uncore

00:01.0 PCI bridge [0604]: Intel Corporation 6th-10th Gen Core Processor PCIe Controller (x16) [8086:1901] (rev 05) (prog-if 00 [Normal decode])
	Subsystem: Fujitsu Technology Solutions Device [1734:121c]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 121
	IOMMU group: 1
	Bus: primary=00, secondary=01, subordinate=01, sec-latency=0
	I/O behind bridge: e000-efff [size=4K] [16-bit]
	Memory behind bridge: ed000000-ee0fffff [size=17M] [32-bit]
	Prefetchable memory behind bridge: d0000000-e20fffff [size=289M] [32-bit]
	Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
	BridgeCtl: Parity+ SERR+ NoISA- VGA+ VGA16+ MAbort- >Reset- FastB2B-
		PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
	Capabilities: <access denied>
	Kernel driver in use: pcieport

00:14.0 USB controller [0c03]: Intel Corporation 100 Series/C230 Series Chipset Family USB 3.0 xHCI Controller [8086:a12f] (rev 31) (prog-if 30 [XHCI])
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	Interrupt: pin A routed to IRQ 130
	IOMMU group: 2
	Region 0: Memory at ee230000 (64-bit, non-prefetchable) [size=64K]
	Capabilities: <access denied>
	Kernel driver in use: xhci_hcd
	Kernel modules: xhci_pci

00:14.2 Signal processing controller [1180]: Intel Corporation 100 Series/C230 Series Chipset Family Thermal Subsystem [8086:a131] (rev 31)
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O- Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Interrupt: pin C routed to IRQ 18
	IOMMU group: 2
	Region 0: Memory at ee24e000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: intel_pch_thermal
	Kernel modules: intel_pch_thermal

00:16.0 Communication controller [0780]: Intel Corporation 100 Series/C230 Series Chipset Family MEI Controller #1 [8086:a13a] (rev 31)
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	Interrupt: pin A routed to IRQ 140
	IOMMU group: 3
	Region 0: Memory at ee24d000 (64-bit, non-prefetchable) [size=4K]
	Capabilities: <access denied>
	Kernel driver in use: mei_me
	Kernel modules: mei_me

00:17.0 SATA controller [0106]: Intel Corporation Q170/Q150/B150/H170/H110/Z170/CM236 Chipset SATA Controller [AHCI Mode] [8086:a102] (rev 31) (prog-if 01 [AHCI 1.0])
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz+ UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	Interrupt: pin A routed to IRQ 139
	IOMMU group: 4
	Region 0: Memory at ee248000 (32-bit, non-prefetchable) [size=8K]
	Region 1: Memory at ee24c000 (32-bit, non-prefetchable) [size=256]
	Region 2: I/O ports at f050 [size=8]
	Region 3: I/O ports at f040 [size=4]
	Region 4: I/O ports at f020 [size=32]
	Region 5: Memory at ee24b000 (32-bit, non-prefetchable) [size=2K]
	Capabilities: <access denied>
	Kernel driver in use: ahci
	Kernel modules: ahci

00:1d.0 PCI bridge [0604]: Intel Corporation 100 Series/C230 Series Chipset Family PCI Express Root Port #9 [8086:a118] (rev f1) (prog-if 00 [Normal decode])
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 122
	IOMMU group: 5
	Bus: primary=00, secondary=02, subordinate=03, sec-latency=0
	I/O behind bridge: d000-dfff [size=4K] [16-bit]
	Memory behind bridge: e8000000-ec1fffff [size=66M] [32-bit]
	Prefetchable memory behind bridge: [disabled] [64-bit]
	Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
	BridgeCtl: Parity+ SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
		PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
	Capabilities: <access denied>
	Kernel driver in use: pcieport

00:1d.1 PCI bridge [0604]: Intel Corporation 100 Series/C230 Series Chipset Family PCI Express Root Port #10 [8086:a119] (rev f1) (prog-if 00 [Normal decode])
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin B routed to IRQ 123
	IOMMU group: 6
	Bus: primary=00, secondary=04, subordinate=04, sec-latency=0
	I/O behind bridge: c000-cfff [size=4K] [16-bit]
	Memory behind bridge: ee100000-ee1fffff [size=1M] [32-bit]
	Prefetchable memory behind bridge: [disabled] [64-bit]
	Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
	BridgeCtl: Parity+ SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
		PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
	Capabilities: <access denied>
	Kernel driver in use: pcieport

00:1f.0 ISA bridge [0601]: Intel Corporation C236 Chipset LPC/eSPI Controller [8086:a149] (rev 31)
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	IOMMU group: 7

00:1f.2 Memory controller [0580]: Intel Corporation 100 Series/C230 Series Chipset Family Power Management Controller [8086:a121] (rev 31)
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O- Mem- BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	IOMMU group: 7
	Region 0: Memory at ee244000 (32-bit, non-prefetchable) [disabled] [size=16K]

00:1f.3 Audio device [0403]: Intel Corporation 100 Series/C230 Series Chipset Family HD Audio Controller [8086:a170] (rev 31) (prog-if 00 [HDA compatible])
	Subsystem: Fujitsu Technology Solutions Device [1734:121e]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 32, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 141
	IOMMU group: 7
	Region 0: Memory at ee240000 (64-bit, non-prefetchable) [size=16K]
	Region 4: Memory at ee220000 (64-bit, non-prefetchable) [size=64K]
	Capabilities: <access denied>
	Kernel driver in use: snd_hda_intel
	Kernel modules: snd_soc_avs, snd_hda_intel

00:1f.4 SMBus [0c05]: Intel Corporation 100 Series/C230 Series Chipset Family SMBus [8086:a123] (rev 31)
	Subsystem: Fujitsu Technology Solutions Device [1734:121d]
	Control: I/O+ Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap- 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Interrupt: pin A routed to IRQ 16
	IOMMU group: 7
	Region 0: Memory at ee24a000 (64-bit, non-prefetchable) [size=256]
	Region 4: I/O ports at f000 [size=32]
	Kernel driver in use: i801_smbus
	Kernel modules: i2c_i801

00:1f.6 Ethernet controller [0200]: Intel Corporation Ethernet Connection (2) I219-LM [8086:15b7] (rev 31)
	Subsystem: Fujitsu Technology Solutions Device [1734:121f]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	Interrupt: pin A routed to IRQ 124
	IOMMU group: 8
	Region 0: Memory at ee200000 (32-bit, non-prefetchable) [size=128K]
	Capabilities: <access denied>
	Kernel driver in use: e1000e
	Kernel modules: e1000e

01:00.0 VGA compatible controller [0300]: NVIDIA Corporation TU104 [GeForce RTX 2080 Rev. A] [10de:1e87] (rev a1) (prog-if 00 [VGA controller])
	Subsystem: ASUSTeK Computer Inc. Device [1043:8662]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0
	Interrupt: pin A routed to IRQ 142
	IOMMU group: 1
	Region 0: Memory at ed000000 (32-bit, non-prefetchable) [size=16M]
	Region 1: Memory at d0000000 (64-bit, prefetchable) [size=256M]
	Region 3: Memory at e0000000 (64-bit, prefetchable) [size=32M]
	Region 5: I/O ports at e000 [size=128]
	Expansion ROM at 000c0000 [virtual] [disabled] [size=128K]
	Capabilities: <access denied>
	Kernel driver in use: nvidia
	Kernel modules: nvidia

01:00.1 Audio device [0403]: NVIDIA Corporation TU104 HD Audio Controller [10de:10f8] (rev a1) (prog-if 00 [HDA compatible])
	Subsystem: ASUSTeK Computer Inc. Device [1043:8662]
	Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin B routed to IRQ 17
	IOMMU group: 1
	Region 0: Memory at ee080000 (32-bit, non-prefetchable) [size=16K]
	Capabilities: <access denied>
	Kernel driver in use: snd_hda_intel
	Kernel modules: snd_hda_intel

01:00.2 USB controller [0c03]: NVIDIA Corporation TU104 USB 3.1 Host Controller [10de:1ad8] (rev a1) (prog-if 30 [XHCI])
	Subsystem: ASUSTeK Computer Inc. Device [1043:8662]
	Control: I/O- Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Interrupt: pin C routed to IRQ 138
	IOMMU group: 1
	Region 0: Memory at e2000000 (64-bit, prefetchable) [size=256K]
	Region 3: Memory at e2040000 (64-bit, prefetchable) [size=64K]
	Capabilities: <access denied>
	Kernel driver in use: xhci_hcd
	Kernel modules: xhci_pci

01:00.3 Serial bus controller [0c80]: NVIDIA Corporation TU104 USB Type-C UCSI Controller [10de:1ad9] (rev a1)
	Subsystem: ASUSTeK Computer Inc. Device [1043:8662]
	Control: I/O- Mem- BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Interrupt: pin D routed to IRQ 255
	IOMMU group: 1
	Region 0: Memory at ee084000 (32-bit, non-prefetchable) [disabled] [size=4K]
	Capabilities: <access denied>

02:00.0 PCI bridge [0604]: Pericom Semiconductor PI7C9X113SL/PI7C9X118SL PCIe-to-PCI Bridge [12d8:e113] (prog-if 00 [Normal decode])
	Subsystem: Fujitsu Technology Solutions Device [1734:11fe]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 31
	IOMMU group: 9
	Bus: primary=02, secondary=03, subordinate=03, sec-latency=64
	I/O behind bridge: d000-dfff [size=4K] [16-bit]
	Memory behind bridge: e8000000-ec1fffff [size=66M] [32-bit]
	Prefetchable memory behind bridge: [disabled] [64-bit]
	Secondary status: 66MHz+ FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- <SERR- <PERR-
	BridgeCtl: Parity+ SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
		PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
	Capabilities: <access denied>

03:04.0 Multimedia audio controller [0401]: Creative Labs EMU20k1 [Sound Blaster X-Fi Series] [1102:0005]
	Subsystem: Creative Labs Device [1102:002f]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 32 (1000ns min, 1250ns max), Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 31
	IOMMU group: 9
	Region 0: I/O ports at d000 [size=32]
	Region 1: Memory at ec000000 (64-bit, non-prefetchable) [size=2M]
	Region 3: Memory at e8000000 (64-bit, non-prefetchable) [size=64M]
	Capabilities: <access denied>
	Kernel driver in use: snd_ctxfi
	Kernel modules: snd_ctxfi

04:00.0 Ethernet controller [0200]: Intel Corporation I210 Gigabit Network Connection [8086:1533] (rev 03)
	Subsystem: Fujitsu Technology Solutions Device [1734:11fc]
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr+ Stepping- SERR+ FastB2B- DisINTx+
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 17
	IOMMU group: 10
	Region 0: Memory at ee100000 (32-bit, non-prefetchable) [size=512K]
	Region 2: I/O ports at c000 [size=32]
	Region 3: Memory at ee180000 (32-bit, non-prefetchable) [size=16K]
	Capabilities: <access denied>
	Kernel driver in use: igb
	Kernel modules: igb


** USB devices:
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 001 Device 002: ID 2109:2817 VIA Labs, Inc. USB2.0 Hub             
Bus 001 Device 003: ID 2109:2817 VIA Labs, Inc. USB2.0 Hub             
Bus 001 Device 004: ID 067b:2303 Prolific Technology, Inc. PL2303 Serial Port / Mobile Phone Data Cable
Bus 001 Device 005: ID 1a40:0101 Terminus Technology Inc. Hub
Bus 001 Device 006: ID 04a9:190f Canon, Inc. CanoScan LiDE 220
Bus 001 Device 007: ID 046d:c626 Logitech, Inc. 3Dconnexion Space Navigator 3D Mouse
Bus 001 Device 008: ID 1a40:0101 Terminus Technology Inc. Hub
Bus 001 Device 009: ID 040b:6533 Weltrend Semiconductor Speed-Link Competition Pro
Bus 001 Device 010: ID 1a40:0101 Terminus Technology Inc. Hub
Bus 001 Device 011: ID 045e:0719 Microsoft Corp. Xbox 360 Wireless Adapter
Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub
Bus 003 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 004 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub


-- System Information:
Debian Release: forky/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.17.8+deb14-amd64 (SMP w/8 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages linux-image-6.17.8+deb14-amd64 depends on:
ii  initramfs-tools [linux-initramfs-tool]  0.150
ii  kmod                                    34.2-2
ii  linux-base                              4.14

Versions of packages linux-image-6.17.8+deb14-amd64 recommends:
ii  apparmor  4.1.0-1

Versions of packages linux-image-6.17.8+deb14-amd64 suggests:
pn  debian-kernel-handbook  <none>
ii  firmware-linux-free     20241210-2
ii  grub-efi-amd64          2.12-9
pn  linux-doc-6.17          <none>

Versions of packages linux-image-6.17.8+deb14-amd64 is related to:
ii  firmware-amd-graphics      20251021-1
pn  firmware-atheros           <none>
pn  firmware-bnx2              <none>
pn  firmware-bnx2x             <none>
pn  firmware-brcm80211         <none>
pn  firmware-cavium            <none>
pn  firmware-cirrus            <none>
ii  firmware-intel-graphics    20251021-1
ii  firmware-intel-misc        20251021-1
ii  firmware-intel-sound       20251021-1
pn  firmware-ipw2x00           <none>
pn  firmware-ivtv              <none>
pn  firmware-iwlwifi           <none>
pn  firmware-libertas          <none>
pn  firmware-marvell-prestera  <none>
ii  firmware-mediatek          20251021-1
ii  firmware-misc-nonfree      20251021-1
pn  firmware-myricom           <none>
pn  firmware-netronome         <none>
pn  firmware-netxen            <none>
ii  firmware-nvidia-graphics   20251021-1
pn  firmware-qcom-soc          <none>
pn  firmware-qlogic            <none>
pn  firmware-realtek           <none>
pn  firmware-samsung           <none>
pn  firmware-siano             <none>
pn  firmware-ti-connectivity   <none>
pn  xen-hypervisor             <none>

-- no debconf information

[toc] | [next] | [standalone]


#90326 — Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-11-29 09:10 +0100
SubjectBug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48
Message-ID<LWobL-gAl5-1@gated-at.bofh.it>
In reply to#90313
Hi,

On Fri, Nov 28, 2025 at 08:32:21PM +0100, Salvatore Bonaccorso wrote:
> Hi Takeshi,
> 
> On Fri, Nov 28, 2025 at 06:24:43PM +0100, Takashi Iwai wrote:
> > On Fri, 28 Nov 2025 07:07:36 +0100,
> > Salvatore Bonaccorso wrote:
> > > 
> > > Hi Jaroslav, hi Takashi
> > > 
> > > A user in Debian reported (in https://bugs.debian.org/1121535) an
> > > array-index-out-of-bounds affecting ctxfi/ctamixer.c:
> > > 
> > > On Fri, Nov 28, 2025 at 12:06:07AM +0100, waxhead wrote:
> > > >  ------------[ cut here ]------------
> > > > Nov 27 23:46:53 main kernel: UBSAN: array-index-out-of-bounds in /build/reproducible-path/linux-6.17.8/sound/pci/ctxfi/ctamixer.c:347:48
> > > > Nov 27 23:46:53 main kernel: index 8 is out of range for type 'unsigned char [8]'
> > > > Nov 27 23:46:53 main kernel: CPU: 4 UID: 0 PID: 468 Comm: (udev-worker) Not tainted 6.17.8+deb14-amd64 #1 PREEMPT(lazy)  Debian 6.17.8-1 
> > > > Nov 27 23:46:53 main kernel: Hardware name: FUJITSU /D3446-S2, BIOS V5.0.0.12 R1.26.0 for D3446-S2x                    02/11/2020
> > > > Nov 27 23:46:53 main kernel: Call Trace:
> > > > Nov 27 23:46:53 main kernel:  <TASK>
> > > > Nov 27 23:46:53 main kernel:  dump_stack_lvl+0x5d/0x80
> > > > Nov 27 23:46:53 main kernel:  ? __pfx_amixer_set_x+0x10/0x10 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  ubsan_epilogue+0x5/0x2b
> > > > Nov 27 23:46:53 main kernel:  __ubsan_handle_out_of_bounds.cold+0x54/0x59
> > > > Nov 27 23:46:53 main kernel:  sum_output_slot+0x44/0x70 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  amixer_set_input+0x4b/0x80 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  amixer_setup+0x1b/0x50 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  ct_mixer_create+0x193/0x570 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  ct_atc_create+0x3cb/0x530 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  ct_card_probe+0x104/0x2c0 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  local_pci_probe+0x3f/0x90
> > > > Nov 27 23:46:53 main kernel:  pci_device_probe+0xda/0x2b0
> > > > Nov 27 23:46:53 main kernel:  ? sysfs_do_create_link_sd+0x6d/0xd0
> > > > Nov 27 23:46:53 main kernel:  really_probe+0xdb/0x340
> > > > Nov 27 23:46:53 main kernel:  ? pm_runtime_barrier+0x55/0x90
> > > > Nov 27 23:46:53 main kernel:  __driver_probe_device+0x78/0x140
> > > > Nov 27 23:46:53 main kernel:  driver_probe_device+0x1f/0xa0
> > > > Nov 27 23:46:53 main kernel:  ? __pfx___driver_attach+0x10/0x10
> > > > Nov 27 23:46:53 main kernel:  __driver_attach+0xcb/0x1e0
> > > > Nov 27 23:46:53 main kernel:  bus_for_each_dev+0x82/0xd0
> > > > Nov 27 23:46:53 main kernel:  bus_add_driver+0x10b/0x1f0
> > > > Nov 27 23:46:53 main kernel:  ? __pfx_ct_driver_init+0x10/0x10 [snd_ctxfi]
> > > > Nov 27 23:46:53 main kernel:  driver_register+0x75/0xe0
> > > > Nov 27 23:46:53 main kernel:  do_one_initcall+0x58/0x300
> > > > Nov 27 23:46:53 main kernel:  do_init_module+0x62/0x250
> > > > Nov 27 23:46:53 main kernel:  ? init_module_from_file+0x8a/0xe0
> > > > Nov 27 23:46:53 main kernel:  init_module_from_file+0x8a/0xe0
> > > > Nov 27 23:46:53 main kernel:  idempotent_init_module+0x114/0x310
> > > > Nov 27 23:46:53 main kernel:  __x64_sys_finit_module+0x6d/0xd0
> > > > Nov 27 23:46:53 main kernel:  ? syscall_trace_enter+0x8d/0x1d0
> > > > Nov 27 23:46:53 main kernel:  do_syscall_64+0x82/0x320
> > > > Nov 27 23:46:53 main kernel:  ? restore_fpregs_from_fpstate+0x46/0xa0
> > > > Nov 27 23:46:53 main kernel:  ? switch_fpu_return+0x5b/0xe0
> > > > Nov 27 23:46:53 main kernel:  ? do_syscall_64+0x200/0x320
> > > > Nov 27 23:46:53 main kernel:  ? exc_page_fault+0x74/0x180
> > > > Nov 27 23:46:53 main kernel:  entry_SYSCALL_64_after_hwframe+0x76/0x7e
> > > > Nov 27 23:46:53 main kernel: RIP: 0033:0x7f77238f3779
> > > > Nov 27 23:46:53 main kernel: Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 4f 86 0d 00 f7 d8 64 89 01 48
> > > > Nov 27 23:46:53 main kernel: RSP: 002b:00007ffc398103f8 EFLAGS: 00000246 ORIG_RAX: 0000000000000139
> > > > Nov 27 23:46:53 main kernel: RAX: ffffffffffffffda RBX: 000055e0eb622480 RCX: 00007f77238f3779
> > > > Nov 27 23:46:53 main kernel: RDX: 0000000000000004 RSI: 00007f77239f744d RDI: 000000000000001b
> > > > Nov 27 23:46:53 main kernel: RBP: 0000000000000004 R08: 0000000000000000 R09: 00007f7723ef6280
> > > > Nov 27 23:46:53 main kernel: R10: 0000000000000000 R11: 0000000000000246 R12: 00007f77239f744d
> > > > Nov 27 23:46:53 main kernel: R13: 0000000000020000 R14: 000055e0eb61e630 R15: 0000000000000000
> > > > Nov 27 23:46:53 main kernel:  </TASK>
> > > > Nov 27 23:46:53 main kernel: ---[ end trace ]---
> > > 
> > > This was specifically with 6.17.8 but up to the current stable 6.17.9
> > > there should be no related changes afaics.
> > 
> > Thanks for the report.  As a wild guess, a simple fix like below
> > should suffice for this case?
> > 
> > 
> > Takashi
> > 
> > -- 8< --
> > --- a/sound/pci/ctxfi/ctamixer.h
> > +++ b/sound/pci/ctxfi/ctamixer.h
> > @@ -22,7 +22,7 @@
> >  /* Define the descriptor of a summation node resource */
> >  struct sum {
> >  	struct rsc rsc;		/* Basic resource info */
> > -	unsigned char idx[8];
> > +	unsigned char idx[8 + 1]; /* msr + master */
> >  };
> >  
> >  /* Define sum resource request description info */
> 
> FWIW, I cannot test this myself.  "waxhead", can you please test the
> proposed patch and report back if it fixes the issue for you?

In case you need some support on how to actually do that, we have the
"simple patching and building" instruction here:
https://kernel-team.pages.debian.net/kernel-handbook/ch-common-tasks.html#id-1.6.6.4

Proceed as follow, create the patch file as posted by Takashi, save it
as e.g. ubsan-fix.patch

Fetch the linux source

apt-get source linux
cd linux-*

Make sure the required dependencies are installed see the above
preparation step in 4.5.1, that is 

apt-get install build-essential
apt-get build-dep linux
apt-get install devscripts

then within the unpacked linux source run the test-patches script
using the proposed patch:

debian/bin/test-patches ../ubsan-fix.patch

Let me know if you can proceed with that.

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#90588 — Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48

FromKarsten Hohmeier <linux@hohmatik.de>
Date2025-12-26 22:40 +0100
SubjectBug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48
Message-ID<M6nHr-5SMY-1@gated-at.bofh.it>
In reply to#90326
Hello. I am another affected user.
I applied the suggested patch by Takeshi on top of 6.18.2 (in case it got already fixed).

But this just gives

> Dez 26 17:24:13: dtest kernel: UBSAN: array-index-out-of-bounds in sound/pci/ctxfi/ctamixer.c:344:48
> Dez 26 17:24:13: dtest kernel: index 10 is out of range for type 'unsigned char [9]'

as the error. Making the struct even larger gives

> Dez 26 17:39:35 dtest kernel: UBSAN: array-index-out-of-bounds in sound/pci/ctxfi/ctamixer.c:344:48
> Dez 26 17:39:35 dtest kernel: index 32 is out of range for type 'unsigned char [32]'

Could you take another look?

Regards

Karsten

[toc] | [prev] | [next] | [standalone]


#90762 — Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48

FromKarsten Hohmeier <linux@hohmatik.de>
Date2026-01-10 11:50 +0100
SubjectBug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48
Message-ID<MbEHD-9uDM-5@gated-at.bofh.it>
In reply to#90313
Hello Takashi.

Thank you for the suggested patch.
I should have access to the affected machine next weekend and will test it then.

Regards

Karsten

[toc] | [prev] | [next] | [standalone]


#90866 — Bug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48

FromKarsten Hohmeier <linux@hohmatik.de>
Date2026-01-18 20:00 +0100
SubjectBug#1121535: UBSAN: array-index-out-of-bounds in [...]sound/pci/ctxfi/ctamixer.c:347:48
Message-ID<MeGad-bwHh-1@gated-at.bofh.it>
In reply to#90313
Hello Takashi,

Your second patch works. Boot messages are gone and the soundcard still works as usual.
Thumbs up from me for upstreaming this.

Karsten

[toc] | [prev] | [next] | [standalone]


#91051 — Bug#1121535: marked as done (linux-image-6.17.8+deb14-amd64: array-index-out-of-bounds trace during boot (...ctamixer.c:347:48))

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2026-02-03 22:40 +0100
SubjectBug#1121535: marked as done (linux-image-6.17.8+deb14-amd64: array-index-out-of-bounds trace during boot (...ctamixer.c:347:48))
Message-ID<MkwhR-fw4X-47@gated-at.bofh.it>
In reply to#90313

[Multipart message — attachments visible in raw view] — view raw

Your message dated Tue, 03 Feb 2026 21:30:07 +0000
with message-id <E1vnNyJ-00000001ytV-2G0Q@fasolo.debian.org>
and subject line Bug#1121535: fixed in linux 6.19~rc7-1~exp1
has caused the Debian Bug report #1121535,
regarding linux-image-6.17.8+deb14-amd64: array-index-out-of-bounds trace during boot (...ctamixer.c:347:48)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1121535: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121535
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web