lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 11 Jul 2017 09:47:17 -0700 From: Guenter Roeck <linux@...ck-us.net> To: Laurent Pinchart <laurent.pinchart@...asonboard.com> Cc: Richard Simmons <rssimmo@...zon.com>, Mauro Carvalho Chehab <mchehab@...nel.org>, linux-media@...r.kernel.org, linux-kernel@...r.kernel.org, Robb Glasser <rglasser@...gle.com> Subject: Re: [PATCH v2] [media] uvcvideo: Prevent heap overflow in uvc driver Any comments / feedback ? Thanks, Guenter On Fri, Jun 30, 2017 at 09:21:56AM -0700, Guenter Roeck wrote: > The size of uvc_control_mapping is user controlled leading to a > potential heap overflow in the uvc driver. This adds a check to verify > the user provided size fits within the bounds of the defined buffer > size. > > Originally-from: Richard Simmons <rssimmo@...zon.com> > Signed-off-by: Guenter Roeck <linux@...ck-us.net> > --- > Fixes CVE-2017-0627. > > v2: Combination of v1 with the fix suggested by Richard Simmons > Perform validation after uvc_ctrl_fill_xu_info() > Take into account that ctrl->info.size is in bytes > Also validate mapping->size > > drivers/media/usb/uvc/uvc_ctrl.c | 7 +++++++ > 1 file changed, 7 insertions(+) > > diff --git a/drivers/media/usb/uvc/uvc_ctrl.c b/drivers/media/usb/uvc/uvc_ctrl.c > index c2ee6e39fd0c..d3e3164f43fd 100644 > --- a/drivers/media/usb/uvc/uvc_ctrl.c > +++ b/drivers/media/usb/uvc/uvc_ctrl.c > @@ -2002,6 +2002,13 @@ int uvc_ctrl_add_mapping(struct uvc_video_chain *chain, > goto done; > } > > + /* validate that the user provided bit-size and offset is valid */ > + if (mapping->size > 32 || > + mapping->offset + mapping->size > ctrl->info.size * 8) { > + ret = -EINVAL; > + goto done; > + } > + > list_for_each_entry(map, &ctrl->info.mappings, list) { > if (mapping->id == map->id) { > uvc_trace(UVC_TRACE_CONTROL, "Can't add mapping '%s', " > -- > 2.7.4 >
Powered by blists - more mailing lists