On Mon Jul 6 13:57:10 2026 +0100, Sean Young wrote:
> The length and offset is provided by the usb device, so it should be
> validated.
>
> Fixes: 2154be651b90 ("[media] redrat3: new rc-core IR transceiver device
> driver")
> Signed-off-by: Sean Young <[email protected]>
> Cc: [email protected]
> Reviewed-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Sean Young
drivers/media/rc/redrat3.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
---
diff --git a/drivers/media/rc/redrat3.c b/drivers/media/rc/redrat3.c
index 3f828a564e19..658e223a4745 100644
--- a/drivers/media/rc/redrat3.c
+++ b/drivers/media/rc/redrat3.c
@@ -358,8 +358,24 @@ static void redrat3_process_ir_data(struct redrat3_dev
*rr3)
/* process each rr3 encoded byte into an int */
sig_size = be16_to_cpu(rr3->irdata.sig_size);
+
+ /*
+ * Note we are not checking if we are reading beyond the end of the
+ * packet which was sent, and reading stale data. If the device
+ * sends a packet which is short then we get garbage IR, but no
+ * out of bounds read.
+ */
+ if (sig_size > RR3_MAX_SIG_SIZE) {
+ dev_err(dev, "length %u is incorrect\n", sig_size);
+ return;
+ }
+
for (i = 0; i < sig_size; i++) {
offset = rr3->irdata.sigdata[i];
+ if (offset >= RR3_DRIVER_MAXLENS) {
+ dev_err(dev, "offset %u is incorrect\n", offset);
+ return;
+ }
val = get_unaligned_be16(&rr3->irdata.lens[offset]);
/* we should always get pulse/space/pulse/space samples */
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]