Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1497405

[PATCH 18/26] gp8psk: don't go past the buffer size

From Mauro Carvalho Chehab <mchehab@s-opensource.com>
Newsgroups linux.kernel
Subject [PATCH 18/26] gp8psk: don't go past the buffer size
Date 2016-10-07 19:30 +0200
Message-ID <spH86-3EG-49@gated-at.bofh.it> (permalink)
References <spH85-3EG-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Add checks to avoid going out of the buffer.

Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
---
 drivers/media/usb/dvb-usb/gp8psk.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/drivers/media/usb/dvb-usb/gp8psk.c b/drivers/media/usb/dvb-usb/gp8psk.c
index fa215ad37f7b..a745cf636846 100644
--- a/drivers/media/usb/dvb-usb/gp8psk.c
+++ b/drivers/media/usb/dvb-usb/gp8psk.c
@@ -60,6 +60,9 @@ int gp8psk_usb_in_op(struct dvb_usb_device *d, u8 req, u16 value, u16 index, u8
 	struct gp8psk_state *st = d->priv;
 	int ret = 0,try = 0;
 
+	if (blen > sizeof(st->data))
+		return -EIO;
+
 	if ((ret = mutex_lock_interruptible(&d->usb_mutex)))
 		return ret;
 
@@ -98,6 +101,9 @@ int gp8psk_usb_out_op(struct dvb_usb_device *d, u8 req, u16 value,
 	deb_xfer("out: req. %x, val: %x, ind: %x, buffer: ",req,value,index);
 	debug_dump(b,blen,deb_xfer);
 
+	if (blen > sizeof(st->data))
+		return -EIO;
+
 	if ((ret = mutex_lock_interruptible(&d->usb_mutex)))
 		return ret;
 
@@ -151,6 +157,11 @@ static int gp8psk_load_bcm4500fw(struct dvb_usb_device *d)
 			err("failed to load bcm4500 firmware.");
 			goto out_free;
 		}
+		if (buflen > 64) {
+			err("firmare chunk size bigger than 64 bytes.");
+			goto out_free;
+		}
+
 		memcpy(buf, ptr, buflen);
 		if (dvb_usb_generic_write(d, buf, buflen)) {
 			err("failed to load bcm4500 firmware.");
-- 
2.7.4

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 00/26] Don't use stack for DMA transers on dvb-usb drivers Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
  [PATCH 21/26] pctv452e: don't call BUG_ON() on non-fatal error Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
    [PATCH v2 21/26] pctv452e: don't call BUG_ON() on non-fatal error Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-08 12:20 +0200
  [PATCH 26/26] digitv: handle error code on RC query Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
  [PATCH 06/26] cxusb: don't do DMA on stack Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
    Re: [PATCH 06/26] cxusb: don't do DMA on stack Patrick Boettcher <patrick.boettcher@posteo.de> - 2016-10-10 08:40 +0200
  [PATCH 01/26] af9005: don't do DMA on stack Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
  [PATCH 11/26] digitv: don't do DMA on stack Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
    Re: [PATCH 11/26] digitv: don't do DMA on stack Patrick Boettcher <patrick.boettcher@posteo.de> - 2016-10-10 08:40 +0200
  [PATCH 02/26] cinergyT2-core: don't do DMA on stack Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
    Re: [PATCH 02/26] cinergyT2-core: don't do DMA on stack Patrick Boettcher <patrick.boettcher@posteo.de> - 2016-10-10 08:40 +0200
  [PATCH 15/26] dtt200u: handle USB control message errors Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
  [PATCH 14/26] dtt200u: don't do DMA on stack Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
    Re: [PATCH 14/26] dtt200u: don't do DMA on stack Patrick Boettcher <patrick.boettcher@posteo.de> - 2016-10-10 08:40 +0200
  [PATCH 04/26] cinergyT2-fe: cache stats at cinergyt2_fe_read_status() Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
  [PATCH 18/26] gp8psk: don't go past the buffer size Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:30 +0200
  [PATCH 07/26] dib0700: be sure that dib0700_ctrl_rd() users can do DMA Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:40 +0200
    Re: [PATCH 07/26] dib0700: be sure that dib0700_ctrl_rd() users can  do DMA Patrick Boettcher <patrick.boettcher@posteo.de> - 2016-10-10 08:40 +0200
  [PATCH 17/26] gp8psk: don't do DMA on stack Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:40 +0200
  [PATCH 23/26] dvb-usb: warn if return value for USB read/write routines is not checked Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-10-07 19:40 +0200

csiph-web