summaryrefslogtreecommitdiff
path: root/libuvc-cve-2026-1991.patch
diff options
context:
space:
mode:
Diffstat (limited to 'libuvc-cve-2026-1991.patch')
-rw-r--r--libuvc-cve-2026-1991.patch32
1 files changed, 32 insertions, 0 deletions
diff --git a/libuvc-cve-2026-1991.patch b/libuvc-cve-2026-1991.patch
new file mode 100644
index 0000000..7ba1374
--- /dev/null
+++ b/libuvc-cve-2026-1991.patch
@@ -0,0 +1,32 @@
+diff -Naur a/src/device.c b/src/device.c
+--- a/src/device.c 2023-04-01 09:38:41.000000000 +0800
++++ b/src/device.c 2026-10-09 12:30:29.305857770 +0800
+@@ -1328,11 +1328,28 @@
+
+ ret = UVC_SUCCESS;
+
++ /* The interface index comes from untrusted descriptor data parsed by
++ * uvc_parse_vc_header(); validate it (and info->config) before
++ * dereferencing info->config->interface[]. A malformed descriptor would
++ * otherwise make the pointer arithmetic below yield an out-of-range
++ * address and crash (CVE-2026-1991, address 0x10 with info->config NULL).
++ */
++ if (info->config == NULL || interface_idx < 0 ||
++ interface_idx >= (int)info->config->bNumInterfaces) {
++ UVC_EXIT(UVC_ERROR_INVALID_PARAM);
++ return UVC_ERROR_INVALID_PARAM;
++ }
++
+ if_desc = &(info->config->interface[interface_idx].altsetting[0]);
+ buffer = if_desc->extra;
+ buffer_left = if_desc->extra_length;
+
+ stream_if = calloc(1, sizeof(*stream_if));
++ if (stream_if == NULL) {
++ UVC_EXIT(UVC_ERROR_NO_MEM);
++ return UVC_ERROR_NO_MEM;
++ }
++
+ stream_if->parent = info;
+ stream_if->bInterfaceNumber = if_desc->bInterfaceNumber;
+ DL_APPEND(info->stream_ifs, stream_if);