On Wed Jul 1 20:45:36 2026 +0900, HyeongJun An wrote:
> s2255_fillbuff() memcpy()s vc->jpg_size bytes of a captured JPEG/MJPEG
> frame into the vb2 plane. vc->jpg_size is taken verbatim from the
> S2255_MARKER_FRAME header the device sends (pdword[4] in save_frame())
> and, unlike the frame payload length just above it, is never bounded:
>
> payload = le32_to_cpu(pdword[3]);
> if (payload > vc->req_image_size) /* payload is checked ... */
> return -EINVAL;
> vc->pkt_size = payload;
> vc->jpg_size = le32_to_cpu(pdword[4]); /* ... jpg_size is not */
>
> A malicious or malfunctioning device can therefore report a jpg_size
> larger than the destination vb2 plane, and the memcpy() writes past it.
> jpg_size is a signed int, so a value with the top bit set also turns
> into a huge length.
>
> Reject a frame whose jpg_size is negative or exceeds the plane size
> before copying it.
>
> Fixes: 38f993ad8b1f ("V4L/DVB (8125): This driver adds support for the
> Sensoray 2255 devices.")
> Cc: [email protected]
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: HyeongJun An <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/usb/s2255/s2255drv.c | 6 ++++++
1 file changed, 6 insertions(+)
---
diff --git a/drivers/media/usb/s2255/s2255drv.c
b/drivers/media/usb/s2255/s2255drv.c
index 68cc4ea5b459..15012d73975c 100644
--- a/drivers/media/usb/s2255/s2255drv.c
+++ b/drivers/media/usb/s2255/s2255drv.c
@@ -612,6 +612,12 @@ static void s2255_fillbuff(struct s2255_vc *vc,
break;
case V4L2_PIX_FMT_JPEG:
case V4L2_PIX_FMT_MJPEG:
+ if (jpgsize < 0 ||
+ jpgsize > vb2_plane_size(&buf->vb.vb2_buf, 0)) {
+ dprintk(dev, 1, "bad JPEG frame size %d\n",
+ jpgsize);
+ break;
+ }
vb2_set_plane_payload(&buf->vb.vb2_buf, 0, jpgsize);
memcpy(vbuf, tmpbuf, jpgsize);
break;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]