mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] media: uvcvideo: Fix bounds for descriptor parsing
@ 2026-09-11 13:23 Ricardo Ribalda
  2026-09-28 12:02 ` Laurent Pinchart
  0 siblings, 1 reply; 12+ messages in thread
From: Ricardo Ribalda @ 2026-09-11 13:23 UTC (permalink / raw)
  To: Laurent Pinchart, Hans de Goede, Mauro Carvalho Chehab
  Cc: Laurent Pinchart, linux-media, linux-kernel, stable, Ricardo Ribalda

uvc_parse_control() passes descriptor by descriptor to
uvc_parse_standard_control() with the number of bytes remaining in the
buffer, not the number of bytes of that descriptor.

Because of this, malformed descriptors could leak over the next
descriptor, leaving malformed data in our structures.

Change the code so we pass the actual length of the descriptor to the
parser.

Note that this makes the existing check more strict and some devices
that are wrongly parsed today will not be probed now.

Cc: stable@vger.kernel.org
Fixes: c0efd232929c ("V4L/DVB (8145a): USB Video Class driver")
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
---
 drivers/media/usb/uvc/uvc_driver.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/drivers/media/usb/uvc/uvc_driver.c b/drivers/media/usb/uvc/uvc_driver.c
index e289cc71ba98..429f1ab19a2a 100644
--- a/drivers/media/usb/uvc/uvc_driver.c
+++ b/drivers/media/usb/uvc/uvc_driver.c
@@ -1248,11 +1248,14 @@ static int uvc_parse_control(struct uvc_device *dev)
 	 */
 
 	while (buflen > 2) {
-		if (uvc_parse_vendor_control(dev, buffer, buflen) ||
+		if (buflen < buffer[0] || buffer[0] < 3)
+			return -EINVAL;
+
+		if (uvc_parse_vendor_control(dev, buffer, buffer[0]) ||
 		    buffer[1] != USB_DT_CS_INTERFACE)
 			goto next_descriptor;
 
-		ret = uvc_parse_standard_control(dev, buffer, buflen);
+		ret = uvc_parse_standard_control(dev, buffer, buffer[0]);
 		if (ret < 0)
 			return ret;
 

---
base-commit: 27953c044974baf7e24dee3e9342fe0103dea80c
change-id: 20260911-uvc-ctrl-bound-9c1940f06fc7

Best regards,
-- 
Ricardo Ribalda <ribalda@chromium.org>


^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-09-28 19:55 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-11 13:23 [PATCH] media: uvcvideo: Fix bounds for descriptor parsing Ricardo Ribalda
2026-09-28 12:02 ` Laurent Pinchart
2026-09-28 12:10   ` Ricardo Ribalda
2026-09-28 12:24     ` Laurent Pinchart
2026-09-28 12:35       ` Ricardo Ribalda
2026-09-28 12:41         ` Laurent Pinchart
2026-09-28 14:03           ` Ricardo Ribalda
2026-09-28 18:44             ` Laurent Pinchart
2026-09-28 19:03               ` Ricardo Ribalda
2026-09-28 19:44                 ` Laurent Pinchart
2026-09-28 19:49                   ` Ricardo Ribalda
2026-09-28 19:55                     ` Laurent Pinchart

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®