From patchwork Mon Mar 13 12:53:58 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Johan Hovold X-Patchwork-Id: 39997 X-Patchwork-Delegate: hverkuil@xs4all.nl Received: from mail.tu-berlin.de ([130.149.7.33]) by www.linuxtv.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cnPVt-0005Ey-Re; Mon, 13 Mar 2017 12:55:49 +0000 X-tubIT-Incoming-IP: 209.132.180.67 Received: from vger.kernel.org ([209.132.180.67]) by mail.tu-berlin.de (exim-4.84_2/mailfrontend-6) with esmtp id 1cnPVr-0005ea-5F; Mon, 13 Mar 2017 13:55:49 +0100 Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752561AbdCMMzU (ORCPT + 1 other); Mon, 13 Mar 2017 08:55:20 -0400 Received: from mail-lf0-f68.google.com ([209.85.215.68]:36574 "EHLO mail-lf0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750927AbdCMMyg (ORCPT ); Mon, 13 Mar 2017 08:54:36 -0400 Received: by mail-lf0-f68.google.com with SMTP id g70so11735196lfh.3; Mon, 13 Mar 2017 05:54:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references; bh=SNuHHpGsDfhflejzjy02/PuKzQL8lwnIU/6O2Nihrc8=; b=WKLf6Q8o5xN0WiphBLuJ/pUJfVIILm2HVfdSO3M+s6vzTc8euXlrgqPZkxf8DHSrMY XrxC58It6Fqy7qu+NllZuqquCPJHBk5vETyVwZWVGAEd/1bcynvEbGCSPCb7yjhx3IMt zJKgPv0fDselSOWriCkULT6Rcbbv8Fwl1voIcFp9NgQwNCbLINbzspRA3/D8Zfigc5wF DypOVFslxsTrF4irxOzpKJGpoGRyq6AUU97LQkUMtE/heNOf4r90FnuBdlJMgZGUlvUe QBKS18aEP3oMHpTBWEgfdevEttpyr09KYJ/oLIJDKm5xvewbHo+ALMtB4YXHDCwtFrdO 5qFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references; bh=SNuHHpGsDfhflejzjy02/PuKzQL8lwnIU/6O2Nihrc8=; b=GsZkfxzsLq7sOqdQkTxWcaLxqPuXiq7fRNEwKn0xvO+2GR1M4nPUVY2iXQAaxYU+wb qDDupAY6ktgM9f0cxO3hvdzz8RfwpS/ggG3XQD9SlkGjrDEv4SGFpQhvzQijkWvMclvl yiN5ROhdqsxmvPF+Fe32yAn6i3UiaDqdYcMGIAThA1xz8kNgctBllwoz9rN3A9QXR/k4 YTlMvZNOvsfynogk5FC0j0XEll5VSELaLay9bPtDYlIhuJftwu+RrvK/IhbJ7XCumwP+ 4ENyQtSgw1/PX3L9z+a3l2a/GaVn2NeV14+ENZDI2h3kohwNAwSKmrfcqscbK6zKuuUY doSA== X-Gm-Message-State: AMke39nm7UgH4Qv/k77vtXXl4sZvN802fH8IDJGZKiUW0O962TTRJq1W8IqhQZIHN9as0g== X-Received: by 10.25.151.196 with SMTP id z187mr8179667lfd.126.1489409673653; Mon, 13 Mar 2017 05:54:33 -0700 (PDT) Received: from xi.terra ([84.216.234.102]) by smtp.gmail.com with ESMTPSA id l78sm3585494lfl.59.2017.03.13.05.54.30 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 13 Mar 2017 05:54:31 -0700 (PDT) Received: from johan by xi.terra with local (Exim 4.89) (envelope-from ) id 1cnPUU-0007fF-C7; Mon, 13 Mar 2017 13:54:22 +0100 From: Johan Hovold To: Mauro Carvalho Chehab Cc: Hans Verkuil , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, Johan Hovold , stable , Sri Deevi Subject: [PATCH 5/6] [media] cx231xx-audio: fix NULL-deref at probe Date: Mon, 13 Mar 2017 13:53:58 +0100 Message-Id: <20170313125359.29394-6-johan@kernel.org> X-Mailer: git-send-email 2.12.0 In-Reply-To: <20170313125359.29394-1-johan@kernel.org> References: <20170313125359.29394-1-johan@kernel.org> Sender: linux-media-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-media@vger.kernel.org X-PMX-Version: 6.0.0.2142326, Antispam-Engine: 2.7.2.2107409, Antispam-Data: 2017.3.13.124518 X-PMX-Spam: Gauge=IIIIIIII, Probability=8%, Report=' MULTIPLE_RCPTS 0.1, HTML_00_01 0.05, HTML_00_10 0.05, BODYTEXTP_SIZE_3000_LESS 0, BODY_SIZE_1700_1799 0, BODY_SIZE_2000_LESS 0, BODY_SIZE_5000_LESS 0, BODY_SIZE_7000_LESS 0, DKIM_SIGNATURE 0, ECARD_WORD 0, FROM_SAME_AS_TO_DOMAIN 0, IN_REP_TO 0, LEGITIMATE_SIGNS 0, MSG_THREAD 0, MULTIPLE_REAL_RCPTS 0, NO_URI_HTTPS 0, REFERENCES 0, __ANY_URI 0, __CC_NAME 0, __CC_NAME_DIFF_FROM_ACC 0, __CC_REAL_NAMES 0, __FROM_DOMAIN_IN_ANY_CC2 0, __FROM_DOMAIN_IN_ANY_TO2 0, __FROM_DOMAIN_IN_RCPT 0, __HAS_CC_HDR 0, __HAS_FROM 0, __HAS_LIST_ID 0, __HAS_MSGID 0, __HAS_X_MAILER 0, __HAS_X_MAILING_LIST 0, __IN_REP_TO 0, __MIME_TEXT_ONLY 0, __MIME_TEXT_P 0, __MIME_TEXT_P1 0, __MULTIPLE_RCPTS_CC_X2 0, __NO_HTML_TAG_RAW 0, __REFERENCES 0, __SANE_MSGID 0, __SUBJ_ALPHA_END 0, __TO_MALFORMED_2 0, __TO_NAME 0, __TO_NAME_DIFF_FROM_ACC 0, __TO_REAL_NAMES 0, __TO_SAME_AS_FROM_DOMAIN 0, __URI_NO_WWW 0, __URI_NS , __YOUTUBE_RCVD 0' Make sure to check the number of endpoints to avoid dereferencing a NULL-pointer or accessing memory beyond the endpoint array should a malicious device lack the expected endpoints. Fixes: e0d3bafd0258 ("V4L/DVB (10954): Add cx231xx USB driver") Cc: stable # 2.6.30 Cc: Sri Deevi Signed-off-by: Johan Hovold --- drivers/media/usb/cx231xx/cx231xx-audio.c | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/drivers/media/usb/cx231xx/cx231xx-audio.c b/drivers/media/usb/cx231xx/cx231xx-audio.c index f3729d6eb46a..a050d125934c 100644 --- a/drivers/media/usb/cx231xx/cx231xx-audio.c +++ b/drivers/media/usb/cx231xx/cx231xx-audio.c @@ -697,6 +697,11 @@ static int cx231xx_audio_init(struct cx231xx *dev) hs_config_info[0].interface_info. audio_index + 1]; + if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1) { + err = -ENODEV; + goto err_free_card; + } + adev->end_point_addr = uif->altsetting[0].endpoint[isoc_pipe].desc. bEndpointAddress; @@ -712,8 +717,14 @@ static int cx231xx_audio_init(struct cx231xx *dev) } for (i = 0; i < adev->num_alt; i++) { - u16 tmp = - le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].desc. + u16 tmp; + + if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1) { + err = -ENODEV; + goto err_free_pkt_size; + } + + tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].desc. wMaxPacketSize); adev->alt_max_pkt_size[i] = (tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1); @@ -724,6 +735,8 @@ static int cx231xx_audio_init(struct cx231xx *dev) return 0; +err_free_pkt_size: + kfree(adev->alt_max_pkt_size); err_free_card: snd_card_free(card);