On Tue Jun 30 15:19:33 2026 +0800, Pengpeng Hou wrote:
> compress_sliced_buf() scans one byte at a time while testing a four-byte
> VBI start code. The final iterations can read beyond the remaining
> buffer tail.
>
> Stop the scan once fewer than four bytes remain.
>
> Signed-off-by: Pengpeng Hou <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/pci/ivtv/ivtv-vbi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
---
diff --git a/drivers/media/pci/ivtv/ivtv-vbi.c
b/drivers/media/pci/ivtv/ivtv-vbi.c
index ae7a00f46257..af086c4cbe1a 100644
--- a/drivers/media/pci/ivtv/ivtv-vbi.c
+++ b/drivers/media/pci/ivtv/ivtv-vbi.c
@@ -330,7 +330,7 @@ static u32 compress_sliced_buf(struct ivtv *itv, u32 line,
u8 *buf, u32 size, u8
unsigned lines = 0;
/* find the first valid line */
- for (i = 0; i < size; i++, buf++) {
+ for (i = 0; i + 3 < size; i++, buf++) {
if (buf[0] == 0xff && !buf[1] && !buf[2] && buf[3] == sav)
break;
}
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]