On Wed Jul 1 20:45:36 2026 +0900, HyeongJun An wrote:
> s2255_fillbuff() memcpy()s vc->jpg_size bytes of a captured JPEG/MJPEG
> frame into the vb2 plane.  vc->jpg_size is taken verbatim from the
> S2255_MARKER_FRAME header the device sends (pdword[4] in save_frame())
> and, unlike the frame payload length just above it, is never bounded:
> 
>         payload = le32_to_cpu(pdword[3]);
>         if (payload > vc->req_image_size)       /* payload is checked ... */
>                 return -EINVAL;
>         vc->pkt_size = payload;
>         vc->jpg_size = le32_to_cpu(pdword[4]);  /* ... jpg_size is not */
> 
> A malicious or malfunctioning device can therefore report a jpg_size
> larger than the destination vb2 plane, and the memcpy() writes past it.
> jpg_size is a signed int, so a value with the top bit set also turns
> into a huge length.
> 
> Reject a frame whose jpg_size is negative or exceeds the plane size
> before copying it.
> 
> Fixes: 38f993ad8b1f ("V4L/DVB (8125): This driver adds support for the 
> Sensoray 2255 devices.")
> Cc: [email protected]
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: HyeongJun An <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/s2255/s2255drv.c | 6 ++++++
 1 file changed, 6 insertions(+)

---

diff --git a/drivers/media/usb/s2255/s2255drv.c 
b/drivers/media/usb/s2255/s2255drv.c
index 68cc4ea5b459..15012d73975c 100644
--- a/drivers/media/usb/s2255/s2255drv.c
+++ b/drivers/media/usb/s2255/s2255drv.c
@@ -612,6 +612,12 @@ static void s2255_fillbuff(struct s2255_vc *vc,
                        break;
                case V4L2_PIX_FMT_JPEG:
                case V4L2_PIX_FMT_MJPEG:
+                       if (jpgsize < 0 ||
+                           jpgsize > vb2_plane_size(&buf->vb.vb2_buf, 0)) {
+                               dprintk(dev, 1, "bad JPEG frame size %d\n",
+                                       jpgsize);
+                               break;
+                       }
                        vb2_set_plane_payload(&buf->vb.vb2_buf, 0, jpgsize);
                        memcpy(vbuf, tmpbuf, jpgsize);
                        break;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to