The branch main has been updated by bapt:

URL: 
https://cgit.FreeBSD.org/src/commit/?id=8468152509a0dfd73e69618af2b1d7f9cbd366f7

commit 8468152509a0dfd73e69618af2b1d7f9cbd366f7
Author:     Baptiste Daroussin <[email protected]>
AuthorDate: 2026-07-24 14:30:07 +0000
Commit:     Baptiste Daroussin <[email protected]>
CommitDate: 2026-07-24 15:07:50 +0000

    uvideo: fix step=0 infinite loop and int overflow in fbuf_size
    
    Prevent infinite loop in uvideo_vs_negotiation() when a USB camera reports
    step=0 in its continuous frame interval descriptor.
    Cast fbuf_size calculation to uint64_t to avoid int overflow for large
    width/height/bpp combinations.
    
    Reported by:    emaste
---
 sys/dev/usb/video/uvideo.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/sys/dev/usb/video/uvideo.c b/sys/dev/usb/video/uvideo.c
index 7c7268454ae2..bb52232e153e 100644
--- a/sys/dev/usb/video/uvideo.c
+++ b/sys/dev/usb/video/uvideo.c
@@ -1744,7 +1744,7 @@ uvideo_vs_parse_desc_frame_buffer_size(struct 
uvideo_softc *sc,
         * width * height * bpp since dwMaxVideoFrameBufferSize may be wrong.
         */
        if (desc->bDescriptorSubtype == UDESCSUB_VS_FRAME_UNCOMPRESSED) {
-               fbuf_size = UGETW(fd->u.uc.wWidth) *
+               fbuf_size = (uint64_t)UGETW(fd->u.uc.wWidth) *
                    UGETW(fd->u.uc.wHeight) *
                    sc->sc_fmtgrp[fmtidx].format->u.uc.bBitsPerPixel / NBBY;
        } else
@@ -2037,6 +2037,8 @@ uvideo_vs_negotiation(struct uvideo_softc *sc, int commit)
                        else if (frame_ival >= max)
                                frame_ival = max;
                        else {
+                               if (step == 0)
+                                       step = 1;
                                for (i = min;
                                    i + step / 2 < frame_ival;
                                    i += step)

Reply via email to