From patchwork Tue Jun 16 13:12:43 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Paul Elder X-Patchwork-Id: 4058 Return-Path: Received: from perceval.ideasonboard.com (perceval.ideasonboard.com [213.167.242.64]) by lancelot.ideasonboard.com (Postfix) with ESMTPS id E640961F24 for ; Tue, 16 Jun 2020 15:13:26 +0200 (CEST) Authentication-Results: lancelot.ideasonboard.com; dkim=pass (1024-bit key; unprotected) header.d=ideasonboard.com header.i=@ideasonboard.com header.b="RqIi8Hx0"; dkim-atps=neutral Received: from jade.flets-east.jp (unknown [IPv6:2400:4051:61:600:2807:bdfa:f6a:8e53]) by perceval.ideasonboard.com (Postfix) with ESMTPSA id 72E83F9; Tue, 16 Jun 2020 15:13:25 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ideasonboard.com; s=mail; t=1592313206; bh=Vg+VhUMfWG85xqFp+x3bZG6byHh7LtUaycY5Sws99SQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=RqIi8Hx0skHbaLAl7tPBMUG/dFQBffqTlt2CIBohLZ9aupqJUMXHTrr7qhU2C3lm+ qiB62pIrCafFMHj6IuJq/HlbJjUUti0OPE6lEgMS1D4w9qN4GhFRT1HXXO2CHNhsMT c3yJYVhFGUYP2Enp411gDwUXMaASvKcIA6hxqooo= From: Paul Elder To: libcamera-devel@lists.libcamera.org Date: Tue, 16 Jun 2020 22:12:43 +0900 Message-Id: <20200616131244.70308-15-paul.elder@ideasonboard.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: <20200616131244.70308-1-paul.elder@ideasonboard.com> References: <20200616131244.70308-1-paul.elder@ideasonboard.com> MIME-Version: 1.0 Subject: [libcamera-devel] [PATCH 14/15] v4l2: v4l2_camera_proxy: Check arg->index bounds for querybuf, qbuf, dqbuf X-BeenThere: libcamera-devel@lists.libcamera.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 16 Jun 2020 13:13:27 -0000 There were no bounds checks for the index argument for VIDIOC_QUERYBUF, VIDIOC_QBUF, and VIDIOC_DQBUF. Add them. Signed-off-by: Paul Elder Reviewed-by: Jacopo Mondi Reviewed-by: Laurent Pinchart --- src/v4l2/v4l2_camera_proxy.cpp | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/src/v4l2/v4l2_camera_proxy.cpp b/src/v4l2/v4l2_camera_proxy.cpp index 81f9282..e4d534a 100644 --- a/src/v4l2/v4l2_camera_proxy.cpp +++ b/src/v4l2/v4l2_camera_proxy.cpp @@ -588,6 +588,9 @@ int V4L2CameraProxy::vidioc_querybuf(int fd, struct v4l2_buffer *arg) if (arg == nullptr) return -EFAULT; + if (arg->index >= bufferCount_) + return -EINVAL; + int ret = lock(fd); if (ret < 0) return ret; @@ -610,6 +613,9 @@ int V4L2CameraProxy::vidioc_qbuf(int fd, struct v4l2_buffer *arg) if (arg == nullptr) return -EFAULT; + if (arg->index >= bufferCount_) + return -EINVAL; + int ret = lock(fd); if (ret < 0) return ret; @@ -639,6 +645,9 @@ int V4L2CameraProxy::vidioc_dqbuf(int fd, struct v4l2_buffer *arg) if (!streaming_) return -EINVAL; + if (arg->index >= bufferCount_) + return -EINVAL; + int ret = lock(fd); if (ret < 0) return ret;