On Wed May 20 10:25:44 2026 -0400, Henri A wrote:
> Commit eac69475b01f ("media: rc: igorplugusb: heed coherency
> rules") changed the control request storage from an embedded struct to
> an allocated pointer so it can obey DMA coherency rules.
>
> However, the driver still passes &ir->request to usb_fill_control_urb().
> That points the URB setup packet at the pointer field itself rather than
> at the allocated struct usb_ctrlrequest.
>
> USB core then interprets pointer bytes as the setup packet. This can
> produce an invalid bRequestType and trigger the control direction warning
> reported by syzbot:
>
> usb 2-1: BOGUS control dir, pipe 80003580 doesn't match bRequestType 0
>
> Pass ir->request itself as the setup packet.
>
> Fixes: eac69475b01f ("media: rc: igorplugusb: heed coherency rules")
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=11f0e4f957c7c3bf3d51
> Tested-by: [email protected]
> Cc: [email protected]
> Assisted-by: Codex:GPT-5.5
> Signed-off-by: Henri A <[email protected]>
> Signed-off-by: Sean Young <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/rc/igorplugusb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
---
diff --git a/drivers/media/rc/igorplugusb.c b/drivers/media/rc/igorplugusb.c
index 3e10f6fe89f8..b5117ee9f5fa 100644
--- a/drivers/media/rc/igorplugusb.c
+++ b/drivers/media/rc/igorplugusb.c
@@ -184,7 +184,7 @@ static int igorplugusb_probe(struct usb_interface *intf,
if (!ir->buf_in)
goto fail;
usb_fill_control_urb(ir->urb, udev,
- usb_rcvctrlpipe(udev, 0), (uint8_t *)&ir->request,
+ usb_rcvctrlpipe(udev, 0), (uint8_t *)ir->request,
ir->buf_in, MAX_PACKET, igorplugusb_callback, ir);
usb_make_path(udev, ir->phys, sizeof(ir->phys));
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]