On Mon Jul 6 13:57:10 2026 +0100, Sean Young wrote:
> The length and offset is provided by the usb device, so it should be
> validated.
> 
> Fixes: 2154be651b90 ("[media] redrat3: new rc-core IR transceiver device 
> driver")
> Signed-off-by: Sean Young <[email protected]>
> Cc: [email protected]
> Reviewed-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Sean Young

 drivers/media/rc/redrat3.c | 16 ++++++++++++++++
 1 file changed, 16 insertions(+)

---

diff --git a/drivers/media/rc/redrat3.c b/drivers/media/rc/redrat3.c
index 3f828a564e19..658e223a4745 100644
--- a/drivers/media/rc/redrat3.c
+++ b/drivers/media/rc/redrat3.c
@@ -358,8 +358,24 @@ static void redrat3_process_ir_data(struct redrat3_dev 
*rr3)
 
        /* process each rr3 encoded byte into an int */
        sig_size = be16_to_cpu(rr3->irdata.sig_size);
+
+       /*
+        * Note we are not checking if we are reading beyond the end of the
+        * packet which was sent, and reading stale data. If the device
+        * sends a packet which is short then we get garbage IR, but no
+        * out of bounds read.
+        */
+       if (sig_size > RR3_MAX_SIG_SIZE) {
+               dev_err(dev, "length %u is incorrect\n", sig_size);
+               return;
+       }
+
        for (i = 0; i < sig_size; i++) {
                offset = rr3->irdata.sigdata[i];
+               if (offset >= RR3_DRIVER_MAXLENS) {
+                       dev_err(dev, "offset %u is incorrect\n", offset);
+                       return;
+               }
                val = get_unaligned_be16(&rr3->irdata.lens[offset]);
 
                /* we should always get pulse/space/pulse/space samples */
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to