On Thu Aug 27 22:59:10 2026 +0800, Shengzhuo Wei wrote:
> go7007_usb_i2c_master_xfer() copies msgs[i].len bytes into go->usb_buf,
> a 16-byte buffer embedded in struct go7007, without any length check.
> The adapter declares no transfer limits, so an SMBus block transfer
> issued through /dev/i2c-N can write up to 34 bytes into it and corrupt
> the struct fields that follow the buffer.
> 
> Bound the transfer size with i2c_adapter_quirks so the I2C core
> rejects oversized messages before they reach the driver.
> 
> Fixes: 7955f03d18d1 ("[media] go7007: move out of staging into 
> drivers/media/usb.")
> Cc: [email protected]
> Signed-off-by: Shengzhuo Wei <[email protected]>
> Assisted-by: GLM:5.3
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/go7007/go7007-usb.c | 6 ++++++
 1 file changed, 6 insertions(+)

---

diff --git a/drivers/media/usb/go7007/go7007-usb.c 
b/drivers/media/usb/go7007/go7007-usb.c
index c0cb92fa6ab9..867548d655b3 100644
--- a/drivers/media/usb/go7007/go7007-usb.c
+++ b/drivers/media/usb/go7007/go7007-usb.c
@@ -1029,10 +1029,16 @@ static const struct i2c_algorithm go7007_usb_algo = {
        .functionality  = go7007_usb_functionality,
 };
 
+static const struct i2c_adapter_quirks go7007_usb_quirks = {
+       .max_write_len  = 12,
+       .max_read_len   = 15,
+};
+
 static struct i2c_adapter go7007_usb_adap_templ = {
        .owner                  = THIS_MODULE,
        .name                   = "WIS GO7007SB EZ-USB",
        .algo                   = &go7007_usb_algo,
+       .quirks                 = &go7007_usb_quirks,
 };
 
 /********************* USB add/remove functions *********************/
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to