On Fri Aug 14 16:08:02 2026 +0800, Pengpeng Hou wrote:
> Both Cypress Intel HEX parsers read two address bytes from type 04
> records. Generic record framing permits any record length, so a short
> record can make the parser consume the checksum or bytes beyond the
> firmware record. A longer record also violates the Intel HEX type 04
> layout.
> 
> Require the type 04 payload length to be exactly two bytes in both
> implementations.
> 
> Fixes: 79a63c60a6a2 ("[media] media: move dvb-usb-v2/cypress_firmware.c to 
> media/common")
> Fixes: 776338e121b9 ("[PATCH] dvb: Add generalized dvb-usb driver")
> Cc: [email protected]
> Assisted-by: Codex:gpt-5
> Signed-off-by: Pengpeng Hou <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/common/cypress_firmware.c      | 2 ++
 drivers/media/usb/dvb-usb/dvb-usb-firmware.c | 2 ++
 2 files changed, 4 insertions(+)

---

diff --git a/drivers/media/common/cypress_firmware.c 
b/drivers/media/common/cypress_firmware.c
index 66274fdf5243..d0f66ed01c4b 100644
--- a/drivers/media/common/cypress_firmware.c
+++ b/drivers/media/common/cypress_firmware.c
@@ -59,6 +59,8 @@ static int cypress_get_hexline(const struct firmware *fw,
        if (hx->type == 0x04) {
                /* b[4] and b[5] are the Extended linear address record data
                 * field */
+               if (hx->len != 2)
+                       return -EINVAL;
                hx->addr |= (b[4] << 24) | (b[5] << 16);
        }
 
diff --git a/drivers/media/usb/dvb-usb/dvb-usb-firmware.c 
b/drivers/media/usb/dvb-usb/dvb-usb-firmware.c
index 0fb3fa6100e4..675d9d1d4f47 100644
--- a/drivers/media/usb/dvb-usb/dvb-usb-firmware.c
+++ b/drivers/media/usb/dvb-usb/dvb-usb-firmware.c
@@ -141,6 +141,8 @@ int dvb_usb_get_hexline(const struct firmware *fw, struct 
hexline *hx,
 
        if (hx->type == 0x04) {
                /* b[4] and b[5] are the Extended linear address record data 
field */
+               if (hx->len != 2)
+                       return -EINVAL;
                hx->addr |= (b[4] << 24) | (b[5] << 16);
 /*             hx->len -= 2;
                data_offs += 2; */
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to