From: Pengpeng Hou <hppiscas@163.com>
To: mchehab@kernel.org
Cc: linux-media@vger.kernel.org, linux-kernel@vger.kernel.org,
corbet@lwn.net, hppiscas@163.com
Subject: [PATCH v2] media: dvb-frontends: ds3000: validate firmware size
Date: Sun, 20 Sep 2026 11:51:07 +0800 [thread overview]
Message-ID: <20260920035108.20086-1-hppiscas@163.com> (raw)
The firmware diagnostic accesses the first two and last two bytes
without proving that the image contains two bytes. An undersized image
can therefore be read outside its bounds when the diagnostic is enabled.
Reject images smaller than two bytes before the diagnostic or upload
path consumes them.
The issue was found by our static-analysis tool.
Fixes: 09ea33e5c696 ("V4L/DVB (13493): TeVii S470 and TBS 6920 fixes")
Assisted-by: gpt 5
Signed-off-by: Pengpeng Hou <hppiscas@163.com>
---
Changes since v1:
https://lore.kernel.org/all/20260830124034.95459-1-pengpeng@iscas.ac.cn/
Include the tool-discovery and coding-assistance provenance requested by
Jonathan Corbet; retain the two-byte minimum check.
drivers/media/dvb-frontends/ds3000.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/media/dvb-frontends/ds3000.c b/drivers/media/dvb-frontends/ds3000.c
index ce7ae424b27c..9cc97ca7bbcc 100644
--- a/drivers/media/dvb-frontends/ds3000.c
+++ b/drivers/media/dvb-frontends/ds3000.c
@@ -373,6 +373,9 @@ static int ds3000_load_firmware(struct dvb_frontend *fe,
struct ds3000_state *state = fe->demodulator_priv;
int ret = 0;
+ if (fw->size < 2)
+ return -EINVAL;
+
dprintk("%s\n", __func__);
dprintk("Firmware is %zu bytes (%02x %02x .. %02x %02x)\n",
fw->size,
base-commit: 518e5b794c06c0f0eb40df3e202274a66202c137
--
2.50.1 (Apple Git-155)
reply other threads:[~2026-09-20 3:51 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260920035108.20086-1-hppiscas@163.com \
--to=hppiscas@163.com \
--cc=corbet@lwn.net \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®