From: Sean Young <sean@mess.org>
To: linux-media@vger.kernel.org, Sean Young <sean@mess.org>,
Mauro Carvalho Chehab <mchehab@kernel.org>
Cc: Rik van Riel <riel@surriel.com>, linux-kernel@vger.kernel.org
Subject: [PATCH v3 17/17] media: rc: Validate carrier range in LIRC_SET_REC_CARRIER ioctl
Date: Fri, 4 Sep 2026 14:07:45 +0100 [thread overview]
Message-ID: <032aa8fafdbbbf0165862fdd265dc7a4bac161b7.1788526920.git.sean@mess.org> (raw)
In-Reply-To: <cover.1788526920.git.sean@mess.org>
Ensure that the low value of the carrier range is smaller than the
high value. This fixes an underflow in ite_set_rx_carrier_range().
Signed-off-by: Sean Young <sean@mess.org>
---
drivers/media/rc/lirc_dev.c | 2 ++
drivers/media/rc/rc-loopback.c | 5 -----
2 files changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/media/rc/lirc_dev.c b/drivers/media/rc/lirc_dev.c
index 183f1939b941..d9b6ecca563f 100644
--- a/drivers/media/rc/lirc_dev.c
+++ b/drivers/media/rc/lirc_dev.c
@@ -492,6 +492,8 @@ static long lirc_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
ret = -ENOTTY;
else if (val <= 0)
ret = -EINVAL;
+ else if (fh->carrier_low && fh->carrier_low > val)
+ ret = -EINVAL;
else
ret = dev->s_rx_carrier_range(dev, fh->carrier_low,
val);
diff --git a/drivers/media/rc/rc-loopback.c b/drivers/media/rc/rc-loopback.c
index 53d0540717b3..9d56e77c9351 100644
--- a/drivers/media/rc/rc-loopback.c
+++ b/drivers/media/rc/rc-loopback.c
@@ -74,11 +74,6 @@ static int loop_set_rx_carrier_range(struct rc_dev *dev, u32 min, u32 max)
{
struct loopback_dev *lodev = dev->priv;
- if (min < 1 || min > max) {
- dev_dbg(&dev->dev, "invalid rx carrier range %u to %u\n", min, max);
- return -EINVAL;
- }
-
dev_dbg(&dev->dev, "setting rx carrier range %u to %u\n", min, max);
lodev->rxcarriermin = min;
lodev->rxcarriermax = max;
--
2.55.0
prev parent reply other threads:[~2026-09-04 13:08 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 13:07 [PATCH v3 00/17] media: Fix locking issues in rc core Sean Young
2026-09-04 13:07 ` [PATCH v3 01/17] media: rc: Ensure registered is cleared in error path Sean Young
2026-09-04 13:07 ` [PATCH v3 02/17] media: rc: Ensure that rc_unregister_device() does not free input device Sean Young
2026-09-04 13:07 ` [PATCH v3 03/17] media: rc: Fix ABBA deadlock by making locks more fine grained Sean Young
2026-09-04 13:07 ` [PATCH v3 04/17] media: rc: Add missing locking for keymap Sean Young
2026-09-04 13:07 ` [PATCH v3 05/17] media: rc: Fix race between bpf(BPG_PROG_ATTACH) and device unregister Sean Young
2026-09-04 13:07 ` [PATCH v3 06/17] media: rc: mce_kbd: Fix inconsistent locking of keylock Sean Young
2026-09-04 13:07 ` [PATCH v3 07/17] media: ene_ir: Ensure teardown is done in the correct order Sean Young
2026-09-04 13:07 ` [PATCH v3 08/17] media: rc: Use binary search for adding or updating a scancode Sean Young
2026-09-04 13:07 ` [PATCH v3 09/17] media: rc: imon: Bind both interfaces via usb_driver_claim_interface() Sean Young
2026-09-04 13:07 ` [PATCH v3 10/17] media: ir_toy: Remove unused struct field Sean Young
2026-09-04 13:07 ` [PATCH v3 11/17] media: nuvoton-cir: " Sean Young
2026-09-04 13:07 ` [PATCH v3 12/17] media: ite-cir: Removed " Sean Young
2026-09-04 13:07 ` [PATCH v3 13/17] media: fintek-cir: Remove unused fields Sean Young
2026-09-04 13:07 ` [PATCH v3 14/17] media: mceusb: Remove unused field Sean Young
2026-09-04 13:07 ` [PATCH v3 15/17] media: serial_ir: Fix race condition where timer can be re-armed Sean Young
2026-09-04 13:07 ` [PATCH v3 16/17] media: rc: After rc_unregister_device() timers " Sean Young
2026-09-04 13:07 ` Sean Young [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=032aa8fafdbbbf0165862fdd265dc7a4bac161b7.1788526920.git.sean@mess.org \
--to=sean@mess.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=riel@surriel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.