From patchwork Mon Mar 13 12:53:55 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Johan Hovold X-Patchwork-Id: 9620783 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 771EA60244 for ; Mon, 13 Mar 2017 12:56:13 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 67EC92843B for ; Mon, 13 Mar 2017 12:56:13 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 5C63228497; Mon, 13 Mar 2017 12:56:13 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.3 required=2.0 tests=BAYES_00,DKIM_SIGNED, RCVD_IN_DNSWL_HI, RCVD_IN_SORBS_SPAM, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 18FBB2843B for ; Mon, 13 Mar 2017 12:56:13 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751085AbdCMM4F (ORCPT ); Mon, 13 Mar 2017 08:56:05 -0400 Received: from mail-lf0-f68.google.com ([209.85.215.68]:35816 "EHLO mail-lf0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750814AbdCMMye (ORCPT ); Mon, 13 Mar 2017 08:54:34 -0400 Received: by mail-lf0-f68.google.com with SMTP id v2so11774583lfi.2; Mon, 13 Mar 2017 05:54:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references; bh=xvHoXhPyM1Q9N5giP/cSCkdpjrT73psEtEm6RBkIXdE=; b=Uya434eaZmkJtDa+TBODXUHE9uWdezt+0DOMldQ5GnbuvLDfvF8zB6vJdC6rTcI43v BNjty/Jmm5UEL5GgRPlH5lhPUvLEHrmIzsZo0Wilhwr4rhmY1CFNWEB0i/RyAwFNR6ky ZpHozbPUDZQ/JFNNd37D8u+tbElizeTegtXI304PDm21bFtjdFJXjw89uV4sGa8FTQs1 y2F/1GjyRIDC7G6VsDWdXmTvblXH1ia+jxcrk5ZgrakRTVs0TDLHByJdMJGSopPQu2oD /KBPOgoYNnP6pgpSbUBYlzEGBxg5Cl+hz1CrWtGWT5S03H3S/4kUvM71qLJb3odiwbvg gDVA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references; bh=xvHoXhPyM1Q9N5giP/cSCkdpjrT73psEtEm6RBkIXdE=; b=enY9RpWjEqPngzaKuIjF8NyR4jORzkp88yyzEywTeBYX7h5QhjVfy3UVoyVGOoYkRh Q1Cs9/iU4KfQLem9yDgEePF+9dlfGXU1LcRbchVEUgdSBR8+8s9uNiacaMSwS7kDbbTM qxR9oVyAHHdsPBXvq6zEdgJYWB318M8l+Fcxfwd/eSRXur9xpHMfEVsj3eMw9sI2jzPV gWbT1qZ9m3kQEm35zHuEDc7PgEc+PXG70KlgaIaarL0/Eoh5yV9HykbpX3Es1hSmqUOc 20XyKNB12kc68NDgpoEVDyq7YpOk6md0H59Vj32NFppAiBD3gC6DAHvMzbVy3AfzgeI1 eW9Q== X-Gm-Message-State: AMke39m0auGpLjNm1dCsWSDvEHf1GICfYbt5AXNHUqFhyO/veYsJEqMkbyhzEW5i/PQ8Vw== X-Received: by 10.25.31.141 with SMTP id f135mr6768692lff.56.1489409672051; Mon, 13 Mar 2017 05:54:32 -0700 (PDT) Received: from xi.terra ([84.216.234.102]) by smtp.gmail.com with ESMTPSA id 30sm2976866lju.53.2017.03.13.05.54.30 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 13 Mar 2017 05:54:30 -0700 (PDT) Received: from johan by xi.terra with local (Exim 4.89) (envelope-from ) id 1cnPUU-0007f0-3R; Mon, 13 Mar 2017 13:54:22 +0100 From: Johan Hovold To: Mauro Carvalho Chehab Cc: Hans Verkuil , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, Johan Hovold , stable , Thierry MERLE Subject: [PATCH 2/6] [media] usbvision: fix NULL-deref at probe Date: Mon, 13 Mar 2017 13:53:55 +0100 Message-Id: <20170313125359.29394-3-johan@kernel.org> X-Mailer: git-send-email 2.12.0 In-Reply-To: <20170313125359.29394-1-johan@kernel.org> References: <20170313125359.29394-1-johan@kernel.org> Sender: linux-media-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-media@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Make sure to check the number of endpoints to avoid dereferencing a NULL-pointer or accessing memory beyond the endpoint array should a malicious device lack the expected endpoints. Fixes: 2a9f8b5d25be ("V4L/DVB (5206): Usbvision: set alternate interface modification") Cc: stable # 2.6.21 Cc: Thierry MERLE Signed-off-by: Johan Hovold --- drivers/media/usb/usbvision/usbvision-video.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/media/usb/usbvision/usbvision-video.c b/drivers/media/usb/usbvision/usbvision-video.c index f5c635a67d74..f9c3325aa4d4 100644 --- a/drivers/media/usb/usbvision/usbvision-video.c +++ b/drivers/media/usb/usbvision/usbvision-video.c @@ -1501,7 +1501,14 @@ static int usbvision_probe(struct usb_interface *intf, } for (i = 0; i < usbvision->num_alt; i++) { - u16 tmp = le16_to_cpu(uif->altsetting[i].endpoint[1].desc. + u16 tmp; + + if (uif->altsetting[i].desc.bNumEndpoints < 2) { + ret = -ENODEV; + goto err_pkt; + } + + tmp = le16_to_cpu(uif->altsetting[i].endpoint[1].desc. wMaxPacketSize); usbvision->alt_max_pkt_size[i] = (tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);