On Wed May 20 10:25:44 2026 -0400, Henri A wrote:
> Commit eac69475b01f ("media: rc: igorplugusb: heed coherency
> rules") changed the control request storage from an embedded struct to
> an allocated pointer so it can obey DMA coherency rules.
> 
> However, the driver still passes &ir->request to usb_fill_control_urb().
> That points the URB setup packet at the pointer field itself rather than
> at the allocated struct usb_ctrlrequest.
> 
> USB core then interprets pointer bytes as the setup packet. This can
> produce an invalid bRequestType and trigger the control direction warning
> reported by syzbot:
> 
>   usb 2-1: BOGUS control dir, pipe 80003580 doesn't match bRequestType 0
> 
> Pass ir->request itself as the setup packet.
> 
> Fixes: eac69475b01f ("media: rc: igorplugusb: heed coherency rules")
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=11f0e4f957c7c3bf3d51
> Tested-by: [email protected]
> Cc: [email protected]
> Assisted-by: Codex:GPT-5.5
> Signed-off-by: Henri A <[email protected]>
> Signed-off-by: Sean Young <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/rc/igorplugusb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

---

diff --git a/drivers/media/rc/igorplugusb.c b/drivers/media/rc/igorplugusb.c
index 3e10f6fe89f8..b5117ee9f5fa 100644
--- a/drivers/media/rc/igorplugusb.c
+++ b/drivers/media/rc/igorplugusb.c
@@ -184,7 +184,7 @@ static int igorplugusb_probe(struct usb_interface *intf,
        if (!ir->buf_in)
                goto fail;
        usb_fill_control_urb(ir->urb, udev,
-               usb_rcvctrlpipe(udev, 0), (uint8_t *)&ir->request,
+               usb_rcvctrlpipe(udev, 0), (uint8_t *)ir->request,
                ir->buf_in, MAX_PACKET, igorplugusb_callback, ir);
 
        usb_make_path(udev, ir->phys, sizeof(ir->phys));
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to