blob: 7ba1374a81d70445c1c2a626711f4c81b5a8f343 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
|
diff -Naur a/src/device.c b/src/device.c
--- a/src/device.c 2023-04-01 09:38:41.000000000 +0800
+++ b/src/device.c 2026-10-09 12:30:29.305857770 +0800
@@ -1328,11 +1328,28 @@
ret = UVC_SUCCESS;
+ /* The interface index comes from untrusted descriptor data parsed by
+ * uvc_parse_vc_header(); validate it (and info->config) before
+ * dereferencing info->config->interface[]. A malformed descriptor would
+ * otherwise make the pointer arithmetic below yield an out-of-range
+ * address and crash (CVE-2026-1991, address 0x10 with info->config NULL).
+ */
+ if (info->config == NULL || interface_idx < 0 ||
+ interface_idx >= (int)info->config->bNumInterfaces) {
+ UVC_EXIT(UVC_ERROR_INVALID_PARAM);
+ return UVC_ERROR_INVALID_PARAM;
+ }
+
if_desc = &(info->config->interface[interface_idx].altsetting[0]);
buffer = if_desc->extra;
buffer_left = if_desc->extra_length;
stream_if = calloc(1, sizeof(*stream_if));
+ if (stream_if == NULL) {
+ UVC_EXIT(UVC_ERROR_NO_MEM);
+ return UVC_ERROR_NO_MEM;
+ }
+
stream_if->parent = info;
stream_if->bInterfaceNumber = if_desc->bInterfaceNumber;
DL_APPEND(info->stream_ifs, stream_if);
|