32 lines
1.1 KiB
Diff
32 lines
1.1 KiB
Diff
From: Oliver Neukum <oneukum@suse.com>
|
|
Date: Tue, 27 Oct 2015 12:42:38 +0100
|
|
Subject: usbvision fix overflow of interfaces array
|
|
Origin: https://bugzilla.novell.com/attachment.cgi?id=653350
|
|
|
|
This fixes the crash reported in:
|
|
http://seclists.org/bugtraq/2015/Oct/35
|
|
The interface number needs a sanity check.
|
|
|
|
Signed-off-by: Oliver Neukum <oneukum@suse.com>
|
|
[bwh: Backported to 4.2: adjust context]
|
|
---
|
|
drivers/media/usb/usbvision/usbvision-video.c | 7 +++++++
|
|
1 file changed, 7 insertions(+)
|
|
|
|
--- a/drivers/media/usb/usbvision/usbvision-video.c
|
|
+++ b/drivers/media/usb/usbvision/usbvision-video.c
|
|
@@ -1533,6 +1533,13 @@ static int usbvision_probe(struct usb_in
|
|
printk(KERN_INFO "%s: %s found\n", __func__,
|
|
usbvision_device_data[model].model_string);
|
|
|
|
+ /*
|
|
+ * this is a security check.
|
|
+ * an exploit using an incorrect bInterfaceNumber is known
|
|
+ */
|
|
+ if (ifnum >= USB_MAXINTERFACES || !dev->actconfig->interface[ifnum])
|
|
+ return -ENODEV;
|
|
+
|
|
if (usbvision_device_data[model].interface >= 0)
|
|
interface = &dev->actconfig->interface[usbvision_device_data[model].interface]->altsetting[0];
|
|
else
|