public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] Prevent buffer overflow in UVC Gadget setup handler
@ 2022-12-01 12:21 Szymon Heidrich
  2022-12-01 12:28 ` Greg Kroah-Hartman
  2022-12-01 13:49 ` Dan Scally
  0 siblings, 2 replies; 12+ messages in thread
From: Szymon Heidrich @ 2022-12-01 12:21 UTC (permalink / raw)
  To: laurent.pinchart
  Cc: szymon.heidrich, Felipe Balbi, Greg Kroah-Hartman, linux-usb,
	linux-kernel

Setup function uvc_function_setup permits control transfer
requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE),
data stage handler for OUT transfer uses memcpy to copy req->actual
bytes to uvc_event->data.data array of size 60. This may result
in an overflow of 4 bytes.

Signed-off-by: Szymon Heidrich <szymon.heidrich@gmail.com>
---
 drivers/usb/gadget/function/f_uvc.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/gadget/function/f_uvc.c b/drivers/usb/gadget/function/f_uvc.c
index 6e196e061..69c5eb3a3 100644
--- a/drivers/usb/gadget/function/f_uvc.c
+++ b/drivers/usb/gadget/function/f_uvc.c
@@ -216,8 +216,9 @@ uvc_function_ep0_complete(struct usb_ep *ep, struct usb_request *req)
 
 		memset(&v4l2_event, 0, sizeof(v4l2_event));
 		v4l2_event.type = UVC_EVENT_DATA;
-		uvc_event->data.length = req->actual;
-		memcpy(&uvc_event->data.data, req->buf, req->actual);
+		uvc_event->data.length = (req->actual > sizeof(uvc_event->data.data) ?
+			sizeof(uvc_event->data.data) : req->actual);
+		memcpy(&uvc_event->data.data, req->buf, uvc_event->data.length);
 		v4l2_event_queue(&uvc->vdev, &v4l2_event);
 	}
 }
-- 
2.38.1


^ permalink raw reply related	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2022-12-06 21:43 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-12-01 12:21 [PATCH] Prevent buffer overflow in UVC Gadget setup handler Szymon Heidrich
2022-12-01 12:28 ` Greg Kroah-Hartman
2022-12-01 12:44   ` Szymon Heidrich
2022-12-01 13:49 ` Dan Scally
2022-12-01 14:22   ` Szymon Heidrich
2022-12-01 15:45     ` [PATCH v2] usb: gadget: uvc: Prevent buffer overflow in " Szymon Heidrich
2022-12-01 17:54       ` Greg Kroah-Hartman
2022-12-01 19:11         ` Szymon Heidrich
2022-12-06 11:33           ` Dan Scally
2022-12-06 14:13             ` [PATCH v3] " Szymon Heidrich
2022-12-06 21:21               ` Laurent Pinchart
2022-12-06 21:43                 ` Szymon Heidrich

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox