On Fri Sep 11 13:23:50 2026 +0000, Ricardo Ribalda wrote:
> uvc_parse_control() passes descriptor by descriptor to
> uvc_parse_standard_control() with the number of bytes remaining in the
> buffer, not the number of bytes of that descriptor.
> 
> Because of this, malformed descriptors could leak over the next
> descriptor, leaving malformed data in our structures.
> 
> Change the code so we pass the actual length of the descriptor to the
> parser.
> 
> Note that this makes the existing check more strict and some devices
> that are wrongly parsed today will not be probed now.
> 
> Signed-off-by: Ricardo Ribalda <[email protected]>
> Link: 
> https://patch.msgid.link/[email protected]
> Reviewed-by: Laurent Pinchart <[email protected]>
> Signed-off-by: Laurent Pinchart <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/uvc/uvc_driver.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/usb/uvc/uvc_driver.c 
b/drivers/media/usb/uvc/uvc_driver.c
index a056606aee49..468d46dfb9e7 100644
--- a/drivers/media/usb/uvc/uvc_driver.c
+++ b/drivers/media/usb/uvc/uvc_driver.c
@@ -1248,11 +1248,14 @@ static int uvc_parse_control(struct uvc_device *dev)
         */
 
        while (buflen > 2) {
-               if (uvc_parse_vendor_control(dev, buffer, buflen) ||
+               if (buflen < buffer[0] || buffer[0] < 3)
+                       return -EINVAL;
+
+               if (uvc_parse_vendor_control(dev, buffer, buffer[0]) ||
                    buffer[1] != USB_DT_CS_INTERFACE)
                        goto next_descriptor;
 
-               ret = uvc_parse_standard_control(dev, buffer, buflen);
+               ret = uvc_parse_standard_control(dev, buffer, buffer[0]);
                if (ret < 0)
                        return ret;
 
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to