This is an automatic generated email to let you know that the following patch 
were queued at the 
http://git.linuxtv.org/cgit.cgi/v4l-utils.git tree:

Subject: v4l2-ctl-vbi: don't pass uninitialized data to S_FMT on G_FMT failure
Author:  Hans Verkuil <[email protected]>
Date:    Tue Aug 25 08:57:31 2026 +0200

__vbi_set_raw() ignored the result of VIDIOC_G_FMT and passed the
v4l2_format on to VIDIOC_S_FMT/TRY_FMT regardless. The struct is
declared on the stack without an initializer, so if G_FMT fails the
ioctl is issued with whatever happened to be on the stack.

This is easy to trigger: on a vivid VBI capture node with a non
S-Video input selected, raw VBI is not supported and G_FMT returns
EINVAL. --set-fmt-vbi then sends uninitialized sampling_rate, offset,
samples_per_line and start/count values to the driver, e.g.

  S_FMT VBI_CAPTURE: rate=27000000 off=4 spl=1 start0=10 count0=16 \
                     start1=0 count1=0

where offset, samples_per_line and start[1] are stack garbage that
varies between builds.

Bail out when G_FMT fails, and zero-initialize the struct. This
matches what vidcap_get_and_update_fmt() and vidout_set() already do.

Signed-off-by: Hans Verkuil <[email protected]>
Assisted-by: Claude-Code:claude-opus-5

 utils/v4l2-ctl/v4l2-ctl-vbi.cpp | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

---

http://git.linuxtv.org/cgit.cgi/v4l-utils.git/commit/?id=d813b9bb006dd2d6b36f6150c45253248a099623
diff --git a/utils/v4l2-ctl/v4l2-ctl-vbi.cpp b/utils/v4l2-ctl/v4l2-ctl-vbi.cpp
index 6acffe96add9..9aeeb3f79780 100644
--- a/utils/v4l2-ctl/v4l2-ctl-vbi.cpp
+++ b/utils/v4l2-ctl/v4l2-ctl-vbi.cpp
@@ -205,14 +205,15 @@ static void __vbi_set_raw(cv4l_fd &_fd, bool set, bool 
_try, __u32 type,
                          const v4l2_format &raw)
 {
        int fd = _fd.g_fd();
-       v4l2_format fmt;
+       v4l2_format fmt = {};
        int ret;
 
        if (!set && !_try)
                return;
 
        fmt.type = type;
-       doioctl(fd, VIDIOC_G_FMT, &fmt);
+       if (doioctl(fd, VIDIOC_G_FMT, &fmt))
+               return;
        fill_raw_vbi(fmt.fmt.vbi, raw.fmt.vbi);
        if (set)
                ret = doioctl(fd, VIDIOC_S_FMT, &fmt);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to