From nobody Mon Sep 28 08:12:16 2026 Received: from sg-2-1.ptr.blmpb.com (sg-2-1.ptr.blmpb.com [71.18.227.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 66BEB388382 for ; Mon, 24 Aug 2026 19:20:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=71.18.227.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787599243; cv=none; b=m0Rq+UM8Te1oNIwAvvqMZeQRiGTDFUf5UASxyd+Zc1HCfCCEF+fExigCXp+asAPWjUo+8PL57daOK3pDhIgIyDGt6zoKoSBoVA2w6qYLUPjWi23u9jYlMPkjECN49WtGSOpc6PmDed/XMkHDTPMOaBeyRmLN3ez3ImlygPMFnEU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787599243; c=relaxed/simple; bh=SE6RYF4RgqjvqxfmIETCl0Y+EcovjINzHj0ntk3zKQU=; h=Message-Id:Mime-Version:Content-Type:Cc:To:From:Subject:Date; b=OH3vzS7c56aQJjdBqFNzv4wIAgg/ceZuqCJQGjvaL3XyJgOaAYFxF4Ut80i4qe6E9WQDgBErqnJRwr2jmsPMJYDJRoX/D96yeLrfoTBrY7khJWLoJkuBEOy6NMgQ23XRwx2WbPk31gGqvoaNsQcMyOx+v4kGkB3z53I2JWUL3Qk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc; spf=pass smtp.mailfrom=cherr.cc; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b=RsRhVuSY; arc=none smtp.client-ip=71.18.227.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cherr.cc Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b="RsRhVuSY" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=feishu2604220257; d=cherr.cc; t=1787599222; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=eDOkDSGQUi9t79Z89S+frzk+NZ5ly+DCESN3SLosnUE=; b=RsRhVuSY/eQGF48jLbLsfhUf5snDwN8BNoaBGhnX70mhfycr8ynN+P8KhwbpJ6oXOdg01K TfnRRtCqpAQeqUcPzwb9El6c+118SbI/TjrdhHaxjhJ7t4GmSwRq4TDjPWQlDxB0SCFV4H SzL4xZqncxXsYGAgeaep39MIYgKcYDqKgQXHoHSD85Nap5KjxP3z+jUqmVY32vxRBlOhnc RVJyG6tTD8OTWcMFIY6na2+k8+YdKAGRrZTzWVCOGgmWf5XRLZJhG/TjZOfNxiTQoDSRui FTDjIY0t+IwrKmAjwObF4wEcq0Q7qjbYh0CX2VRrQbbED/rDkOZmRENPq4GJ3A== X-Original-From: Shengzhuo Wei Message-Id: <20260825-ttusb-dec-overflow-v2-1-4d1263c03dff@cherr.cc> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Change-Id: 20260825-ttusb-dec-overflow-0d1f7fc2e308 Received: from [192.168.9.107] ([111.42.148.146]) by smtp.feishu.cn with ESMTPS; Tue, 25 Aug 2026 03:20:20 +0800 X-B4-Tracking: v=1; b=H4sIAHCZjGoC/32NQQ7CIBREr9L8tRhAocSV9zBdCHyExBTzqahpu LvYA5hZvUnmzQoFKWGB07ACYU0l5bmD3A3g4nW+IUu+M0guNTdSsWV5Fss8OpYrUrjnF+NehDE 4iQduoA8fhCG9N+ll6hxTWTJ9to8qfu1fXRWsx2ql7FGrUZizi0i0dw6m1toXHZKF0bMAAAA= Cc: , , "Seungjin Bae" , "Pengpeng Hou" , , "Shengzhuo Wei" X-Mailer: b4 0.14.2 Content-Transfer-Encoding: quoted-printable X-Lms-Return-Path: To: "Mauro Carvalho Chehab" From: "Shengzhuo Wei" Subject: [PATCH v2] media: ttusb-dec: reject oversized packet lengths Date: Tue, 25 Aug 2026 03:20:17 +0800 Content-Type: text/plain; charset="utf-8" ttusb_dec_process_urb_frame() derives the packet payload length from the PVA/SECTION header, up to 8 + 0xffff =3D 65543 bytes, and uses it in the bulk-copy state to memcpy() into dec->packet[], a fixed 6148-byte buffer. A malicious or faulty Technotrend TT-USB DEC device can therefore drive a heap out-of-bounds write of up to ~59 KB past the buffer, over function pointers in struct ttusb_dec and adjacent allocations. The only existing length check, in ttusb_dec_process_pva(), runs after the bulk copy, too late to help. Reject the packet in the header state, as soon as the advertised length is known and before any bulk copy. Both PVA and section packets are covered, and the check leaves room for the up-to-five bytes appended after the payload (4-byte trailer plus one padding byte for odd-sized section payloads). Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Reported-by: Seungjin Bae Closes: https://lore.kernel.org/linux-media/20251230195041.36768-2-eeodqql0= 9@gmail.com/ Reported-by: Pengpeng Hou Closes: https://lore.kernel.org/linux-media/20260402112800.39716-1-pengpeng= @iscas.ac.cn/ Assisted-by: GLM:5.3 Signed-off-by: Shengzhuo Wei --- This bug was previously reported and fixes were posted in Dec 2025 and Mar 2026 but did not receive any maintainer response; it is still present in master. This version also rejects section packets (not just PVA) and accounts for the post-payload trailer, which earlier attempts missed. Verified with KASAN: without the check, a crafted packet yields "BUG: KASAN: slab-out-of-bounds ... Write of size 65535"; with the check, the packet is rejected and no overflow occurs. Changes in v2: - The v1 mail carried a corrupted diff (a "\n" in the dev_warn string was expanded into a literal newline), so the patch did not apply. Resend with no other changes. --- drivers/media/usb/ttusb-dec/ttusb_dec.c | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/drivers/media/usb/ttusb-dec/ttusb_dec.c b/drivers/media/usb/tt= usb-dec/ttusb_dec.c index 825a3875989d32ddbb65589f7015acee96a44c9e..58628846d9e23b225c9939784bc= bae7825642fdd 100644 --- a/drivers/media/usb/ttusb-dec/ttusb_dec.c +++ b/drivers/media/usb/ttusb-dec/ttusb_dec.c @@ -700,23 +700,33 @@ static void ttusb_dec_process_urb_frame(struct ttusb_= dec *dec, u8 *b, =20 case 5: dec->packet[dec->packet_length++] =3D *b++; + length--; =20 if (dec->packet_type =3D=3D TTUSB_DEC_PACKET_PVA && dec->packet_length =3D=3D 8) { - dec->packet_state++; dec->packet_payload_length =3D 8 + (dec->packet[6] << 8) + dec->packet[7]; } else if (dec->packet_type =3D=3D TTUSB_DEC_PACKET_SECTION && dec->packet_length =3D=3D 5) { - dec->packet_state++; dec->packet_payload_length =3D 5 + ((dec->packet[3] & 0x0f) << 8) + dec->packet[4]; + } else { + break; + } + + if (dec->packet_payload_length + 5 > + sizeof(dec->packet)) { + dev_warn_ratelimited(&dec->udev->dev, + "%s: packet too long - discarding\n", + __func__); + dec->packet_state =3D 0; + } else { + dec->packet_state++; } =20 - length--; break; =20 case 6: { --- base-commit: 66fb95a521110da673090294561844c9f76ebe64 change-id: 20260825-ttusb-dec-overflow-0d1f7fc2e308 Best regards, --=20 Shengzhuo Wei