summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCoprDistGit <infra@openeuler.org>2026-10-09 04:36:27 +0000
committerCoprDistGit <infra@openeuler.org>2026-10-09 04:36:27 +0000
commitc00affda1228c0bed97fd144cc84b127b19a77e7 (patch)
tree259ac48ea64dd529827cc58313b7d2ca1c136cc7
parentd499ae4032814bd00037c724e720002e2dfb0363 (diff)
automatic import of libuvcopeneuler25.09
-rw-r--r--.gitignore1
-rw-r--r--libuvc-cmake4.patch10
-rw-r--r--libuvc-cve-2026-1991.patch32
-rw-r--r--libuvc.spec62
-rw-r--r--sources1
5 files changed, 106 insertions, 0 deletions
diff --git a/.gitignore b/.gitignore
index e69de29..177ec07 100644
--- a/.gitignore
+++ b/.gitignore
@@ -0,0 +1 @@
+/v0.0.7.tar.gz
diff --git a/libuvc-cmake4.patch b/libuvc-cmake4.patch
new file mode 100644
index 0000000..ca16b44
--- /dev/null
+++ b/libuvc-cmake4.patch
@@ -0,0 +1,10 @@
+diff --git a/CMakeLists.txt b/CMakeLists.txt
+index fbaffc9..9ee0968 100644
+--- a/CMakeLists.txt
++++ b/CMakeLists.txt
+@@ -1,4 +1,4 @@
+-cmake_minimum_required(VERSION 3.1)
++cmake_minimum_required(VERSION 3.1...${CMAKE_VERSION})
+ project(libuvc
+ VERSION 0.0.7
+ LANGUAGES C
diff --git a/libuvc-cve-2026-1991.patch b/libuvc-cve-2026-1991.patch
new file mode 100644
index 0000000..7ba1374
--- /dev/null
+++ b/libuvc-cve-2026-1991.patch
@@ -0,0 +1,32 @@
+diff -Naur a/src/device.c b/src/device.c
+--- a/src/device.c 2023-04-01 09:38:41.000000000 +0800
++++ b/src/device.c 2026-10-09 12:30:29.305857770 +0800
+@@ -1328,11 +1328,28 @@
+
+ ret = UVC_SUCCESS;
+
++ /* The interface index comes from untrusted descriptor data parsed by
++ * uvc_parse_vc_header(); validate it (and info->config) before
++ * dereferencing info->config->interface[]. A malformed descriptor would
++ * otherwise make the pointer arithmetic below yield an out-of-range
++ * address and crash (CVE-2026-1991, address 0x10 with info->config NULL).
++ */
++ if (info->config == NULL || interface_idx < 0 ||
++ interface_idx >= (int)info->config->bNumInterfaces) {
++ UVC_EXIT(UVC_ERROR_INVALID_PARAM);
++ return UVC_ERROR_INVALID_PARAM;
++ }
++
+ if_desc = &(info->config->interface[interface_idx].altsetting[0]);
+ buffer = if_desc->extra;
+ buffer_left = if_desc->extra_length;
+
+ stream_if = calloc(1, sizeof(*stream_if));
++ if (stream_if == NULL) {
++ UVC_EXIT(UVC_ERROR_NO_MEM);
++ return UVC_ERROR_NO_MEM;
++ }
++
+ stream_if->parent = info;
+ stream_if->bInterfaceNumber = if_desc->bInterfaceNumber;
+ DL_APPEND(info->stream_ifs, stream_if);
diff --git a/libuvc.spec b/libuvc.spec
new file mode 100644
index 0000000..1d3f2c6
--- /dev/null
+++ b/libuvc.spec
@@ -0,0 +1,62 @@
+Name: libuvc
+Version: 0.0.7
+Release: 4
+Summary: A cross-platform library for USB video devices
+License: BSD-3-Clause
+URL: https://github.com/libuvc/libuvc
+Source0: https://github.com/libuvc/libuvc/archive/refs/tags/v%{version}.tar.gz
+Patch0: libuvc-cmake4.patch
+Patch1: libuvc-cve-2026-1991.patch
+
+BuildRequires: gcc
+BuildRequires: cmake
+BuildRequires: libusb-devel
+BuildRequires: libjpeg-devel
+
+%description
+A cross-platform library for USB video devices.
+
+%package devel
+Summary: Development files for libuvc
+Requires: %{name}%{?_isa} = %{version}-%{release}
+Conflicts: %{name} < 0.0.7-3
+
+%description devel
+The devel package contains development files for libuvc.
+It provides header files and libraries for libuvc.
+
+%prep
+%autosetup -p1 -n %{name}-%{version}
+
+%build
+%cmake
+%cmake_build
+
+%install
+%cmake_install
+
+%files
+%{_libdir}/*.so.*
+
+%files devel
+%{_includedir}/*
+%{_libdir}/*.so
+%{_libdir}/pkgconfig/*.pc
+%{_libdir}/cmake/*
+%{_libdir}/%{name}.a
+
+%changelog
+* Fri Oct 09 2026 kuyan_kubuds <kuyan@kubuds.cn> - 0.0.7-4
+- Fix CVE-2026-1991: validate info->config and the interface index in
+ uvc_scan_streaming() before dereferencing them. A malformed UVC descriptor
+ caused a NULL pointer dereference (SEGV at address 0x10); see upstream
+ issue libuvc/libuvc#300.
+
+* Sat Jul 18 2026 Funda Wang <fundawang@yeah.net> - 0.0.7-3
+- fix build with cmake 4
+
+* Fri Dec 15 2023 davidhan008 <619409713@qq.com> - 0.0.7-2
+- Add cmake depence
+
+* Wed May 3 2023 will_niutao <niutao2@huawei.com> - 0.0.7-1
+- Init for openEuler
diff --git a/sources b/sources
new file mode 100644
index 0000000..28dd7b7
--- /dev/null
+++ b/sources
@@ -0,0 +1 @@
+19f3255652d447cc9a34737bc5a4c9ab v0.0.7.tar.gz