On Tue Jun 30 14:56:36 2026 +0800, Pengpeng Hou wrote:
> compress_sliced_buf() scans one byte at a time while testing a four-byte
> VBI start code. The final iterations can read beyond the remaining
> buffer tail.
>
> Stop the scan once fewer than four bytes remain.
>
> Signed-off-by: Pengpeng Hou <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/pci/cx18/cx18-vbi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
---
diff --git a/drivers/media/pci/cx18/cx18-vbi.c
b/drivers/media/pci/cx18/cx18-vbi.c
index 8dc4ce325935..3a8430f3259e 100644
--- a/drivers/media/pci/cx18/cx18-vbi.c
+++ b/drivers/media/pci/cx18/cx18-vbi.c
@@ -135,7 +135,7 @@ static u32 compress_sliced_buf(struct cx18 *cx, u8 *buf,
u32 size,
: VBI_HBLANK_SAMPLES_50HZ;
/* find the first valid line */
- for (i = hdr_size, buf += hdr_size; i < size; i++, buf++) {
+ for (i = hdr_size, buf += hdr_size; i + 3 < size; i++, buf++) {
if (buf[0] == 0xff && !buf[1] && !buf[2] &&
(buf[3] == sliced_vbi_eav_rp[0] ||
buf[3] == sliced_vbi_eav_rp[1]))
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]