mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/2] USB: sisusbvga: Fix integer overflow and NULL dereference
@ 2026-02-18  0:55 Vasiliy Kovalev
  2026-02-18  0:55 ` [PATCH 1/2] USB: sisusbvga: Fix integer overflow in sisusb_clear_vram Vasiliy Kovalev
  2026-02-18  0:55 ` [PATCH 2/2] USB: sisusbvga: Fix NULL pointer dereference in sisusb_read Vasiliy Kovalev
  0 siblings, 2 replies; 4+ messages in thread
From: Vasiliy Kovalev @ 2026-02-18  0:55 UTC (permalink / raw)
  To: Thomas Winischhofer, Greg Kroah-Hartman
  Cc: linux-usb, linux-kernel, lvc-project, kovalev

This series fixes two issues in the sisusbvga driver found by static
analysis and confirmed through testing with USB gadget emulation:

1. Integer overflow in boundary check of sisusb_clear_vram() that can be
   triggered by a compromised USB device reporting inflated VRAM size.

2. NULL pointer dereference in sisusb_read() when userspace passes a NULL
   buffer to read(), causing immediate kernel panic.

Both issues are reproducible with the 'USB Gadget Tests' framework [1].

[1] https://github.com/kovalev0/usb-gadget-tests

Vasiliy Kovalev (2):
  USB: sisusbvga: Fix integer overflow in sisusb_clear_vram
  USB: sisusbvga: Fix NULL pointer dereference in sisusb_read

 drivers/usb/misc/sisusbvga/sisusbvga.c | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

-- 
2.50.1


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-02-24  9:14 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-02-18  0:55 [PATCH 0/2] USB: sisusbvga: Fix integer overflow and NULL dereference Vasiliy Kovalev
2026-02-18  0:55 ` [PATCH 1/2] USB: sisusbvga: Fix integer overflow in sisusb_clear_vram Vasiliy Kovalev
2026-02-18  0:55 ` [PATCH 2/2] USB: sisusbvga: Fix NULL pointer dereference in sisusb_read Vasiliy Kovalev
2026-02-24  9:14   ` [lvc-project] " Fedor Pchelkin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®