From c00affda1228c0bed97fd144cc84b127b19a77e7 Mon Sep 17 00:00:00 2001 From: CoprDistGit Date: Fri, 9 Oct 2026 04:36:27 +0000 Subject: automatic import of libuvc --- libuvc-cve-2026-1991.patch | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 libuvc-cve-2026-1991.patch (limited to 'libuvc-cve-2026-1991.patch') diff --git a/libuvc-cve-2026-1991.patch b/libuvc-cve-2026-1991.patch new file mode 100644 index 0000000..7ba1374 --- /dev/null +++ b/libuvc-cve-2026-1991.patch @@ -0,0 +1,32 @@ +diff -Naur a/src/device.c b/src/device.c +--- a/src/device.c 2023-04-01 09:38:41.000000000 +0800 ++++ b/src/device.c 2026-10-09 12:30:29.305857770 +0800 +@@ -1328,11 +1328,28 @@ + + ret = UVC_SUCCESS; + ++ /* The interface index comes from untrusted descriptor data parsed by ++ * uvc_parse_vc_header(); validate it (and info->config) before ++ * dereferencing info->config->interface[]. A malformed descriptor would ++ * otherwise make the pointer arithmetic below yield an out-of-range ++ * address and crash (CVE-2026-1991, address 0x10 with info->config NULL). ++ */ ++ if (info->config == NULL || interface_idx < 0 || ++ interface_idx >= (int)info->config->bNumInterfaces) { ++ UVC_EXIT(UVC_ERROR_INVALID_PARAM); ++ return UVC_ERROR_INVALID_PARAM; ++ } ++ + if_desc = &(info->config->interface[interface_idx].altsetting[0]); + buffer = if_desc->extra; + buffer_left = if_desc->extra_length; + + stream_if = calloc(1, sizeof(*stream_if)); ++ if (stream_if == NULL) { ++ UVC_EXIT(UVC_ERROR_NO_MEM); ++ return UVC_ERROR_NO_MEM; ++ } ++ + stream_if->parent = info; + stream_if->bInterfaceNumber = if_desc->bInterfaceNumber; + DL_APPEND(info->stream_ifs, stream_if); -- cgit v1.2.3