From: Ricardo Ribalda <ribalda@chromium.org>
To: Laurent Pinchart <laurent.pinchart@ideasonboard.com>,
Hans de Goede <hansg@kernel.org>,
Mauro Carvalho Chehab <mchehab@kernel.org>
Cc: Laurent Pinchart <laurent.pinchart@skynet.be>,
linux-media@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org, Ricardo Ribalda <ribalda@chromium.org>
Subject: [PATCH] media: uvcvideo: Fix bounds for descriptor parsing
Date: Fri, 11 Sep 2026 13:23:50 +0000 [thread overview]
Message-ID: <20260911-uvc-ctrl-bound-v1-1-7b5cfc68bae1@chromium.org> (raw)
uvc_parse_control() passes descriptor by descriptor to
uvc_parse_standard_control() with the number of bytes remaining in the
buffer, not the number of bytes of that descriptor.
Because of this, malformed descriptors could leak over the next
descriptor, leaving malformed data in our structures.
Change the code so we pass the actual length of the descriptor to the
parser.
Note that this makes the existing check more strict and some devices
that are wrongly parsed today will not be probed now.
Cc: stable@vger.kernel.org
Fixes: c0efd232929c ("V4L/DVB (8145a): USB Video Class driver")
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
---
drivers/media/usb/uvc/uvc_driver.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/media/usb/uvc/uvc_driver.c b/drivers/media/usb/uvc/uvc_driver.c
index e289cc71ba98..429f1ab19a2a 100644
--- a/drivers/media/usb/uvc/uvc_driver.c
+++ b/drivers/media/usb/uvc/uvc_driver.c
@@ -1248,11 +1248,14 @@ static int uvc_parse_control(struct uvc_device *dev)
*/
while (buflen > 2) {
- if (uvc_parse_vendor_control(dev, buffer, buflen) ||
+ if (buflen < buffer[0] || buffer[0] < 3)
+ return -EINVAL;
+
+ if (uvc_parse_vendor_control(dev, buffer, buffer[0]) ||
buffer[1] != USB_DT_CS_INTERFACE)
goto next_descriptor;
- ret = uvc_parse_standard_control(dev, buffer, buflen);
+ ret = uvc_parse_standard_control(dev, buffer, buffer[0]);
if (ret < 0)
return ret;
---
base-commit: 27953c044974baf7e24dee3e9342fe0103dea80c
change-id: 20260911-uvc-ctrl-bound-9c1940f06fc7
Best regards,
--
Ricardo Ribalda <ribalda@chromium.org>
next reply other threads:[~2026-09-11 13:23 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 13:23 Ricardo Ribalda [this message]
2026-09-28 12:02 ` Laurent Pinchart
2026-09-28 12:10 ` Ricardo Ribalda
2026-09-28 12:24 ` Laurent Pinchart
2026-09-28 12:35 ` Ricardo Ribalda
2026-09-28 12:41 ` Laurent Pinchart
2026-09-28 14:03 ` Ricardo Ribalda
2026-09-28 18:44 ` Laurent Pinchart
2026-09-28 19:03 ` Ricardo Ribalda
2026-09-28 19:44 ` Laurent Pinchart
2026-09-28 19:49 ` Ricardo Ribalda
2026-09-28 19:55 ` Laurent Pinchart
2026-09-28 20:48 ` Ricardo Ribalda
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911-uvc-ctrl-bound-v1-1-7b5cfc68bae1@chromium.org \
--to=ribalda@chromium.org \
--cc=hansg@kernel.org \
--cc=laurent.pinchart@ideasonboard.com \
--cc=laurent.pinchart@skynet.be \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®