On Fri Aug 14 16:08:02 2026 +0800, Pengpeng Hou wrote:
> Both Cypress Intel HEX parsers read two address bytes from type 04
> records. Generic record framing permits any record length, so a short
> record can make the parser consume the checksum or bytes beyond the
> firmware record. A longer record also violates the Intel HEX type 04
> layout.
>
> Require the type 04 payload length to be exactly two bytes in both
> implementations.
>
> Fixes: 79a63c60a6a2 ("[media] media: move dvb-usb-v2/cypress_firmware.c to
> media/common")
> Fixes: 776338e121b9 ("[PATCH] dvb: Add generalized dvb-usb driver")
> Cc: [email protected]
> Assisted-by: Codex:gpt-5
> Signed-off-by: Pengpeng Hou <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/common/cypress_firmware.c | 2 ++
drivers/media/usb/dvb-usb/dvb-usb-firmware.c | 2 ++
2 files changed, 4 insertions(+)
---
diff --git a/drivers/media/common/cypress_firmware.c
b/drivers/media/common/cypress_firmware.c
index 66274fdf5243..d0f66ed01c4b 100644
--- a/drivers/media/common/cypress_firmware.c
+++ b/drivers/media/common/cypress_firmware.c
@@ -59,6 +59,8 @@ static int cypress_get_hexline(const struct firmware *fw,
if (hx->type == 0x04) {
/* b[4] and b[5] are the Extended linear address record data
* field */
+ if (hx->len != 2)
+ return -EINVAL;
hx->addr |= (b[4] << 24) | (b[5] << 16);
}
diff --git a/drivers/media/usb/dvb-usb/dvb-usb-firmware.c
b/drivers/media/usb/dvb-usb/dvb-usb-firmware.c
index 0fb3fa6100e4..675d9d1d4f47 100644
--- a/drivers/media/usb/dvb-usb/dvb-usb-firmware.c
+++ b/drivers/media/usb/dvb-usb/dvb-usb-firmware.c
@@ -141,6 +141,8 @@ int dvb_usb_get_hexline(const struct firmware *fw, struct
hexline *hx,
if (hx->type == 0x04) {
/* b[4] and b[5] are the Extended linear address record data
field */
+ if (hx->len != 2)
+ return -EINVAL;
hx->addr |= (b[4] << 24) | (b[5] << 16);
/* hx->len -= 2;
data_offs += 2; */
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]