[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20170921083739.GI3198@localhost>
Date: Thu, 21 Sep 2017 10:37:39 +0200
From: Johan Hovold <johan@...nel.org>
To: Andrey Konovalov <andreyknvl@...gle.com>
Cc: Mauro Carvalho Chehab <mchehab@...nel.org>,
Oleh Kravchenko <oleg@....org.ua>,
Hans Verkuil <hans.verkuil@...co.com>,
Johan Hovold <johan@...nel.org>, linux-media@...r.kernel.org,
LKML <linux-kernel@...r.kernel.org>,
Dmitry Vyukov <dvyukov@...gle.com>,
Kostya Serebryany <kcc@...gle.com>,
syzkaller <syzkaller@...glegroups.com>
Subject: Re: usb/media/cx231xx: null-ptr-deref in cx231xx_usb_probe
On Wed, Sep 20, 2017 at 08:54:08PM +0200, Andrey Konovalov wrote:
> Hi!
>
> I've got the following report while fuzzing the kernel with syzkaller.
>
> On commit ebb2c2437d8008d46796902ff390653822af6cc4 (Sep 18).
>
> The null-ptr-deref happens on assoc_desc->bFirstInterface, where
> assoc_desc = udev->actconfig->intf_assoc[0]. There seems to be no
> check that the device actually contains an Interface Association
> Descriptor.
That is indeed a bug; I'll respond to this mail with a fix.
Thanks,
Johan
Powered by blists - more mailing lists