From: James Reynolds Date: Tue, 22 Dec 2020 12:07:04 +0000 (+0100) Subject: media: mceusb: Fix potential out-of-bounds shift X-Git-Tag: howlett/maple/20220722_2~3757^2~194 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=1b43bad31fb0e00f45baf5b05bd21eb8d8ce7f58;p=users%2Fjedix%2Flinux-maple.git media: mceusb: Fix potential out-of-bounds shift When processing a MCE_RSP_GETPORTSTATUS command, the bit index to set in ir->txports_cabled comes from response data, and isn't validated. As ir->txports_cabled is a u8, nothing should be done if the bit index is greater than 7. Cc: stable@vger.kernel.org Reported-by: syzbot+ec3b3128c576e109171d@syzkaller.appspotmail.com Signed-off-by: James Reynolds Signed-off-by: Sean Young Signed-off-by: Mauro Carvalho Chehab --- diff --git a/drivers/media/rc/mceusb.c b/drivers/media/rc/mceusb.c index f1dbd059ed08..c8d63673e131 100644 --- a/drivers/media/rc/mceusb.c +++ b/drivers/media/rc/mceusb.c @@ -1169,7 +1169,7 @@ static void mceusb_handle_command(struct mceusb_dev *ir, u8 *buf_in) switch (subcmd) { /* the one and only 5-byte return value command */ case MCE_RSP_GETPORTSTATUS: - if (buf_in[5] == 0) + if (buf_in[5] == 0 && *hi < 8) ir->txports_cabled |= 1 << *hi; break;