From patchwork Mon Mar 13 12:53:54 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Johan Hovold X-Patchwork-Id: 9620765 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 9EB0660522 for ; Mon, 13 Mar 2017 12:54:49 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 8D8A12843B for ; Mon, 13 Mar 2017 12:54:49 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 826F428490; Mon, 13 Mar 2017 12:54:49 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.3 required=2.0 tests=BAYES_00,DKIM_SIGNED, RCVD_IN_DNSWL_HI, RCVD_IN_SORBS_SPAM, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 1397F2848B for ; Mon, 13 Mar 2017 12:54:49 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751037AbdCMMyh (ORCPT ); Mon, 13 Mar 2017 08:54:37 -0400 Received: from mail-lf0-f68.google.com ([209.85.215.68]:36565 "EHLO mail-lf0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750772AbdCMMyd (ORCPT ); Mon, 13 Mar 2017 08:54:33 -0400 Received: by mail-lf0-f68.google.com with SMTP id g70so11735106lfh.3; Mon, 13 Mar 2017 05:54:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references; bh=Z3SvY5Wg7G05GOqoOMP2VkI/qtdAwQdGF3vcBPotb0k=; b=hCdQclcTklblNuExSSDTNfYmniIfGPgEz2rscX+9JhMU9iV+CrLr8yqI+DZlad8+I8 ynTb6tKl+KhrSSaZ7lxoaT2J1LATio2Vx/sTrC97aXeVhwVh+XXesYknC1kwgSO2X33q +WFsO6jol/wYgRSORPs4MWDPRXbqWv9y1jsYNIE3Jsv/DK07clJ1TdMbZiPavPV81Z21 9Syi4bRqf3ck26NHmmle+CJ49p1kSPEI4f+SPLLhHkF4jTSbtPTZ7Rdp5SivwohEqBE7 zMBWz/xEgqJ0PkIXgZqO7NX7Eojmxm2bTBrYngmcO3KLdvfT3tVpMQrHNnvgCtKPLcbO YMmA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references; bh=Z3SvY5Wg7G05GOqoOMP2VkI/qtdAwQdGF3vcBPotb0k=; b=hfCuHyxsFzi49aQzif8obzJUubk8w+CSVIhtBNDMOdO7IrBZQTWiSX/uJeWXoLKWNe 7ufa1UueI5ptTUkOSYj+yb4zo5gKoJ1bFTflB8a4cEHEz2mkUkD98b9XxYod1cPG+JZf 0WGWY/zFAbJ7s1PxgJ08E+2+OGJEnn/JNpJtXH/yZDbv2OacxmRqoQcoDcCjZu7HZhYZ mjq3PLp7TMER7WMozim744a8FICqzJevG0vH7cobvgHcbO1dUnFQUO+uDkzBmuVvH5wD JQvTJlTTsvcUG7BGEYkEptbeSmB+pDGKivqRxOTVoYZXs19KqszPVfbwzALzekd2PLa8 U52Q== X-Gm-Message-State: AMke39kKhdgDPSKYVPEoTOG8LxQfrM541d4LGo54GO0eBosLY1ZjIMbVrht+xkB6on2ciA== X-Received: by 10.25.196.207 with SMTP id u198mr8992791lff.88.1489409671068; Mon, 13 Mar 2017 05:54:31 -0700 (PDT) Received: from xi.terra ([84.216.234.102]) by smtp.gmail.com with ESMTPSA id t1sm3648727lja.36.2017.03.13.05.54.29 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 13 Mar 2017 05:54:30 -0700 (PDT) Received: from johan by xi.terra with local (Exim 4.89) (envelope-from ) id 1cnPUU-0007ew-0b; Mon, 13 Mar 2017 13:54:22 +0100 From: Johan Hovold To: Mauro Carvalho Chehab Cc: Hans Verkuil , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, Johan Hovold , stable Subject: [PATCH 1/6] [media] dib0700: fix NULL-deref at probe Date: Mon, 13 Mar 2017 13:53:54 +0100 Message-Id: <20170313125359.29394-2-johan@kernel.org> X-Mailer: git-send-email 2.12.0 In-Reply-To: <20170313125359.29394-1-johan@kernel.org> References: <20170313125359.29394-1-johan@kernel.org> Sender: linux-media-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-media@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Make sure to check the number of endpoints to avoid dereferencing a NULL-pointer should a malicious device lack endpoints. Fixes: c4018fa2e4c0 ("[media] dib0700: fix RC support on Hauppauge Nova-TD") Cc: stable # 3.16 Cc: Mauro Carvalho Chehab Signed-off-by: Johan Hovold --- drivers/media/usb/dvb-usb/dib0700_core.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/media/usb/dvb-usb/dib0700_core.c b/drivers/media/usb/dvb-usb/dib0700_core.c index dd5edd3a17ee..08acdd32e412 100644 --- a/drivers/media/usb/dvb-usb/dib0700_core.c +++ b/drivers/media/usb/dvb-usb/dib0700_core.c @@ -809,6 +809,9 @@ int dib0700_rc_setup(struct dvb_usb_device *d, struct usb_interface *intf) /* Starting in firmware 1.20, the RC info is provided on a bulk pipe */ + if (intf->altsetting[0].desc.bNumEndpoints < rc_ep + 1) + return -ENODEV; + purb = usb_alloc_urb(0, GFP_KERNEL); if (purb == NULL) return -ENOMEM;