diff options
| author | CoprDistGit <infra@openeuler.org> | 2026-10-09 04:36:27 +0000 |
|---|---|---|
| committer | CoprDistGit <infra@openeuler.org> | 2026-10-09 04:36:27 +0000 |
| commit | c00affda1228c0bed97fd144cc84b127b19a77e7 (patch) | |
| tree | 259ac48ea64dd529827cc58313b7d2ca1c136cc7 | |
| parent | d499ae4032814bd00037c724e720002e2dfb0363 (diff) | |
automatic import of libuvcopeneuler25.09
| -rw-r--r-- | .gitignore | 1 | ||||
| -rw-r--r-- | libuvc-cmake4.patch | 10 | ||||
| -rw-r--r-- | libuvc-cve-2026-1991.patch | 32 | ||||
| -rw-r--r-- | libuvc.spec | 62 | ||||
| -rw-r--r-- | sources | 1 |
5 files changed, 106 insertions, 0 deletions
@@ -0,0 +1 @@ +/v0.0.7.tar.gz diff --git a/libuvc-cmake4.patch b/libuvc-cmake4.patch new file mode 100644 index 0000000..ca16b44 --- /dev/null +++ b/libuvc-cmake4.patch @@ -0,0 +1,10 @@ +diff --git a/CMakeLists.txt b/CMakeLists.txt +index fbaffc9..9ee0968 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -1,4 +1,4 @@ +-cmake_minimum_required(VERSION 3.1) ++cmake_minimum_required(VERSION 3.1...${CMAKE_VERSION}) + project(libuvc + VERSION 0.0.7 + LANGUAGES C diff --git a/libuvc-cve-2026-1991.patch b/libuvc-cve-2026-1991.patch new file mode 100644 index 0000000..7ba1374 --- /dev/null +++ b/libuvc-cve-2026-1991.patch @@ -0,0 +1,32 @@ +diff -Naur a/src/device.c b/src/device.c +--- a/src/device.c 2023-04-01 09:38:41.000000000 +0800 ++++ b/src/device.c 2026-10-09 12:30:29.305857770 +0800 +@@ -1328,11 +1328,28 @@ + + ret = UVC_SUCCESS; + ++ /* The interface index comes from untrusted descriptor data parsed by ++ * uvc_parse_vc_header(); validate it (and info->config) before ++ * dereferencing info->config->interface[]. A malformed descriptor would ++ * otherwise make the pointer arithmetic below yield an out-of-range ++ * address and crash (CVE-2026-1991, address 0x10 with info->config NULL). ++ */ ++ if (info->config == NULL || interface_idx < 0 || ++ interface_idx >= (int)info->config->bNumInterfaces) { ++ UVC_EXIT(UVC_ERROR_INVALID_PARAM); ++ return UVC_ERROR_INVALID_PARAM; ++ } ++ + if_desc = &(info->config->interface[interface_idx].altsetting[0]); + buffer = if_desc->extra; + buffer_left = if_desc->extra_length; + + stream_if = calloc(1, sizeof(*stream_if)); ++ if (stream_if == NULL) { ++ UVC_EXIT(UVC_ERROR_NO_MEM); ++ return UVC_ERROR_NO_MEM; ++ } ++ + stream_if->parent = info; + stream_if->bInterfaceNumber = if_desc->bInterfaceNumber; + DL_APPEND(info->stream_ifs, stream_if); diff --git a/libuvc.spec b/libuvc.spec new file mode 100644 index 0000000..1d3f2c6 --- /dev/null +++ b/libuvc.spec @@ -0,0 +1,62 @@ +Name: libuvc +Version: 0.0.7 +Release: 4 +Summary: A cross-platform library for USB video devices +License: BSD-3-Clause +URL: https://github.com/libuvc/libuvc +Source0: https://github.com/libuvc/libuvc/archive/refs/tags/v%{version}.tar.gz +Patch0: libuvc-cmake4.patch +Patch1: libuvc-cve-2026-1991.patch + +BuildRequires: gcc +BuildRequires: cmake +BuildRequires: libusb-devel +BuildRequires: libjpeg-devel + +%description +A cross-platform library for USB video devices. + +%package devel +Summary: Development files for libuvc +Requires: %{name}%{?_isa} = %{version}-%{release} +Conflicts: %{name} < 0.0.7-3 + +%description devel +The devel package contains development files for libuvc. +It provides header files and libraries for libuvc. + +%prep +%autosetup -p1 -n %{name}-%{version} + +%build +%cmake +%cmake_build + +%install +%cmake_install + +%files +%{_libdir}/*.so.* + +%files devel +%{_includedir}/* +%{_libdir}/*.so +%{_libdir}/pkgconfig/*.pc +%{_libdir}/cmake/* +%{_libdir}/%{name}.a + +%changelog +* Fri Oct 09 2026 kuyan_kubuds <kuyan@kubuds.cn> - 0.0.7-4 +- Fix CVE-2026-1991: validate info->config and the interface index in + uvc_scan_streaming() before dereferencing them. A malformed UVC descriptor + caused a NULL pointer dereference (SEGV at address 0x10); see upstream + issue libuvc/libuvc#300. + +* Sat Jul 18 2026 Funda Wang <fundawang@yeah.net> - 0.0.7-3 +- fix build with cmake 4 + +* Fri Dec 15 2023 davidhan008 <619409713@qq.com> - 0.0.7-2 +- Add cmake depence + +* Wed May 3 2023 will_niutao <niutao2@huawei.com> - 0.0.7-1 +- Init for openEuler @@ -0,0 +1 @@ +19f3255652d447cc9a34737bc5a4c9ab v0.0.7.tar.gz |
