On Fri Sep 11 13:23:50 2026 +0000, Ricardo Ribalda wrote:
> uvc_parse_control() passes descriptor by descriptor to
> uvc_parse_standard_control() with the number of bytes remaining in the
> buffer, not the number of bytes of that descriptor.
>
> Because of this, malformed descriptors could leak over the next
> descriptor, leaving malformed data in our structures.
>
> Change the code so we pass the actual length of the descriptor to the
> parser.
>
> Note that this makes the existing check more strict and some devices
> that are wrongly parsed today will not be probed now.
>
> Signed-off-by: Ricardo Ribalda <[email protected]>
> Link:
> https://patch.msgid.link/[email protected]
> Reviewed-by: Laurent Pinchart <[email protected]>
> Signed-off-by: Laurent Pinchart <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/usb/uvc/uvc_driver.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
---
diff --git a/drivers/media/usb/uvc/uvc_driver.c
b/drivers/media/usb/uvc/uvc_driver.c
index a056606aee49..468d46dfb9e7 100644
--- a/drivers/media/usb/uvc/uvc_driver.c
+++ b/drivers/media/usb/uvc/uvc_driver.c
@@ -1248,11 +1248,14 @@ static int uvc_parse_control(struct uvc_device *dev)
*/
while (buflen > 2) {
- if (uvc_parse_vendor_control(dev, buffer, buflen) ||
+ if (buflen < buffer[0] || buffer[0] < 3)
+ return -EINVAL;
+
+ if (uvc_parse_vendor_control(dev, buffer, buffer[0]) ||
buffer[1] != USB_DT_CS_INTERFACE)
goto next_descriptor;
- ret = uvc_parse_standard_control(dev, buffer, buflen);
+ ret = uvc_parse_standard_control(dev, buffer, buffer[0]);
if (ret < 0)
return ret;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]