On Thu Aug 27 22:59:10 2026 +0800, Shengzhuo Wei wrote:
> go7007_usb_i2c_master_xfer() copies msgs[i].len bytes into go->usb_buf,
> a 16-byte buffer embedded in struct go7007, without any length check.
> The adapter declares no transfer limits, so an SMBus block transfer
> issued through /dev/i2c-N can write up to 34 bytes into it and corrupt
> the struct fields that follow the buffer.
>
> Bound the transfer size with i2c_adapter_quirks so the I2C core
> rejects oversized messages before they reach the driver.
>
> Fixes: 7955f03d18d1 ("[media] go7007: move out of staging into
> drivers/media/usb.")
> Cc: [email protected]
> Signed-off-by: Shengzhuo Wei <[email protected]>
> Assisted-by: GLM:5.3
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/usb/go7007/go7007-usb.c | 6 ++++++
1 file changed, 6 insertions(+)
---
diff --git a/drivers/media/usb/go7007/go7007-usb.c
b/drivers/media/usb/go7007/go7007-usb.c
index c0cb92fa6ab9..867548d655b3 100644
--- a/drivers/media/usb/go7007/go7007-usb.c
+++ b/drivers/media/usb/go7007/go7007-usb.c
@@ -1029,10 +1029,16 @@ static const struct i2c_algorithm go7007_usb_algo = {
.functionality = go7007_usb_functionality,
};
+static const struct i2c_adapter_quirks go7007_usb_quirks = {
+ .max_write_len = 12,
+ .max_read_len = 15,
+};
+
static struct i2c_adapter go7007_usb_adap_templ = {
.owner = THIS_MODULE,
.name = "WIS GO7007SB EZ-USB",
.algo = &go7007_usb_algo,
+ .quirks = &go7007_usb_quirks,
};
/********************* USB add/remove functions *********************/
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]