From nobody Sat Sep 26 00:30:47 2026 Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C69683AE194 for ; Mon, 7 Sep 2026 06:28:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788762522; cv=none; b=pdUyk2lIGWtfwzPscLfsQndbogBCymB4Tv37U79XZc3jM2LVTkJ2y7LhifJA3qjXQfasLVMOrWLhZOQVhLRwUksTNh8RlRZa5ztLO0vxCDRtOylphPhV/G0AjYqug7n5aSlAxhh86yNtYCmuBNBHibhMrGwy+nXwdklHDCgGRtQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788762522; c=relaxed/simple; bh=HQVLVPzjRG5hh8fZIGmX/p3UNdpvdNQwjepL5vkjQ24=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=h2RGmMisDxxOjmzMeUMvMVrGihoc48iV2sSKhK4BnskGlg8FWXmAZLb9RGN7Mi+b6OtsQMNnJTrjF7bk34crU5wSj2rm+WLAmq23zYyH7ePwynXWNlbsOfjstZ8zKNzQSU1RQ+zMZpkBhq7RbwNhMgVvfFkQ0ZXfOI4zeMRlk38= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RwrocECK; arc=none smtp.client-ip=209.85.216.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RwrocECK" Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-39647184c73so3809167a91.1 for ; Sun, 06 Sep 2026 23:28:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788762518; x=1789367318; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=M1wSKmw/x+Nhq5u1uQ+7oGEZmPqsD7MFhh/OKQ0EiNE=; b=RwrocECK6AEI5KhukKMsJQCOLIy9i1qVT7yV9iYiUpxeg3xQhhEGodkJ7Yw8Mp6q14 CzMOm6253xf0zLwIUAhHIy9rX9n4AsC8hY8LmIail2CCwU5LkWCmATG9enClviPymLjb VElL718wfIcogc4u8XH6tfbN4dRGwxAd0v5UadYglREbGEcmeP9qw3/fivdnJ9vqctEG rwjL3rLMRxDGidXib13Fgkwc8zNEWTqIoKxB2eoIGGeJVEOoGFDJTi1aEWsA21Olx61E 1oRVvZLO4z5xF6fraLmQ6SyxNDJTsfTPBG9vQ8O70xoHuoaHp6w2OdzZwRzV3erX9mBy 0uZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788762518; x=1789367318; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=M1wSKmw/x+Nhq5u1uQ+7oGEZmPqsD7MFhh/OKQ0EiNE=; b=VzqPjJ8MhaDbexItlCo8mSPld+55PAMO3TeHyxP14I8KidshzqdLB0zVHGyUuvOK4D 6SUxqAtrXKx66fDlqRF62ewVd0PwjxwDNBFsbq6NL0QNTSTlRh3Z2OGdLza+e6JLrn7L DwqamOqUn/PkaAw7SuSd9LJIdJGd8HKR/Ysjt8zu+YzMgK3iopiH1xautfYl1j9DMV/4 x7N+oQe3ve7+xatcqUEhsOOtBejoR4xW02lKZar9IAk/EArycC+u/ZAgdJfk/D8SCBLf bApooxdPEMWnggkTlanTv0d6kT4+XmRKPWY3NU63plWWnyP1uj9IAUOY0sSSshdqv3/q Y3RA== X-Forwarded-Encrypted: i=1; AKwUvBzTQplooHU8OhIOdDzQK+4wiS5e6gqf+j45KmmiOsazwZEkN/SbZerUF1GvBCm5ACPY5LmMZym3HJXKaQw=@vger.kernel.org X-Gm-Message-State: AFuF++kKSbl0vfkv1LaaMQb1teSOPUVU0jkZ4N96MiBh+Kg10td8xdIM +XQTCK9unMro+LQCzvI5KIX/02xn6eq1N54yzmtsLjtuKoAE9lZaUynKMabTUnhwOIwPbg== X-Gm-Gg: AYBFou1zHrzQ4geTJ0BvkgpZGueRJBzFkz3nS0jtBn80PHi02LjOKhp6/iN/T9egjh9 07KiUlCpf2Zx2H6ngKplq/HaA4YCHwnkGIJDJFKSBZn5ciYORtzP0YiYKPU3om8fwrm9mQhxtPI AP7giTUYMBIG8V8e5qKQ968uSC7Iq13RnRk+5ZtyuNCNpfqZ23l7vHEngtpezj0cE0qwGjUIvAa qKalYy5irgpuxuTMsYxOpNRYoMO/FslmZaaPXmRKGzrYfRn1Ml5EsovClmjXklTbxta+E7gu+6a O80ULE+m3g+eekAyVUnNX/6VaN7qndM09+Hv2hI+OvpEaqfq9havYTsU9xloPc0LzNl8w9ZneHL 6b3MeY9SeQVgDJgaze+PPhI0lhSIFMU2ByplP7RsnVetCWuuS/dkGssDs02IZTKSVX+SYUrY46t MExas59gpzKuOE+d5h58UnMy+6ZosYbptv4GKTu45Km7wh8NQ9EOqdWYu7XdKyY53J3eik8Y1tX c7jXVuMSsxQgLToH1KRD7U7ooncfUxSiPoeV5O79yThQO8RVrFNO0nHNKMdMelminG6DxcL/USE wLg2O14= X-Received: by 2002:a17:90b:2ccd:b0:398:baa7:4c2f with SMTP id 98e67ed59e1d1-39b27c442f8mr16725731a91.5.1788762517830; Sun, 06 Sep 2026 23:28:37 -0700 (PDT) Received: from LAPTOP-UUUVNN1I.localdomain ([129.126.57.197]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39b25c974cfsm18978042a91.0.2026.09.06.23.28.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 06 Sep 2026 23:28:37 -0700 (PDT) From: Wei Jie Law <98lawweijie@gmail.com> To: Laurent Pinchart , Hans de Goede , Mauro Carvalho Chehab Cc: Guennadi Liakhovetski , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 1/2] media: uvcvideo: Fix NULL deref on events for uninitialized controls Date: Mon, 7 Sep 2026 14:28:17 +0800 Message-ID: <20260907062819.2519878-2-98lawweijie@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260907062819.2519878-1-98lawweijie@gmail.com> References: <20260907062819.2519878-1-98lawweijie@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A null-ptr-deref exists in v6.12.105 and upstream. KASAN crash log: KASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087] Workqueue: events uvc_ctrl_status_event_work RIP: 0010:uvc_ctrl_status_event+0x105/0x280 uvc_ctrl_status_event_work+0x82/0x240 process_one_work+0x66f/0x10b0 XU controls are initialized lazily, on the first UVCIOC_CTRL_MAP or UVCIOC_CTRL_QUERY. Until then ctrl->info is all zeroes, so info.mappings is not a valid list head, list_empty() returns false, and uvc_ctrl_status_event() walks it from a NULL next pointer. Fixes: e5225c820c05 ("media: uvcvideo: Send a control event when a Control = Change interrupt arrives") Cc: stable@vger.kernel.org Signed-off-by: Wei Jie Law <98lawweijie@gmail.com> Assisted-by: Claude:claude-opus-5 Reviewed-by: Ricardo Ribalda --- drivers/media/usb/uvc/uvc_ctrl.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/media/usb/uvc/uvc_ctrl.c b/drivers/media/usb/uvc/uvc_c= trl.c index 3ca108b83f1d..21802f9b1b61 100644 --- a/drivers/media/usb/uvc/uvc_ctrl.c +++ b/drivers/media/usb/uvc/uvc_ctrl.c @@ -2209,7 +2209,12 @@ bool uvc_ctrl_status_event_async(struct urb *urb, st= ruct uvc_video_chain *chain, struct uvc_device *dev =3D chain->dev; struct uvc_ctrl_work *w =3D &dev->async_ctrl; =20 - if (list_empty(&ctrl->info.mappings)) + /* + * An uninitialized control has a zeroed info struct, so its + * mappings list head is not a list: list_empty() returns false + * and the walk dereferences NULL. + */ + if (!ctrl->initialized || list_empty(&ctrl->info.mappings)) return false; =20 w->data =3D data; --=20 2.43.0 From nobody Sat Sep 26 00:30:47 2026 Received: from mail-pj1-f49.google.com (mail-pj1-f49.google.com [209.85.216.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CA4F03AE6E9 for ; Mon, 7 Sep 2026 06:28:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788762526; cv=none; b=UldM2OkJpDoi/mC9ztSZFTZBM8jSlPKFFoh2EJ6aXC+90MzKejFvSJZsrrgm8r0v092mYvC8XKM+XsB3rTCXZSnjf7vaZ8yBvVmS1LWPUAcA6qDjacoYaPXltOKLUVSBjW3FhqnUGgfZLyT0esMvpn4JojyYmLJbkVmHIZrdfZ8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788762526; c=relaxed/simple; bh=Eczviqg/1I0bF4Nop5EFAxHliXvYylccF8WSRSrMDJk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qusN3pt9o1la7yiTwo8Y38BJJFUNWUeBeKrdnCURsMbeK8F29Db5Py3WpllrGK2zCWgooFWe7AT1VQXV4t3wKY9+iqwIgaCYzyP/ICIg3IEg3x0GqaciEsyohW6zBCGYXWD+FttoJnsgQhKWFmhyidPom8ALaO0lxhfKzEyYeBs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SWI1vo4Q; arc=none smtp.client-ip=209.85.216.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SWI1vo4Q" Received: by mail-pj1-f49.google.com with SMTP id 98e67ed59e1d1-398b3c37877so2888231a91.0 for ; Sun, 06 Sep 2026 23:28:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788762521; x=1789367321; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EPO3XgKtW39x62BjixAoLRnOdq38lit6qHUtJ4zQNAE=; b=SWI1vo4QtD1kaRxhqS3nwYpllbba9vDiftF/CILJmsfQEspilXMZ2WMrz/w7G1U478 qbFwA54S8iq/jXfVusu4+u3Iz6nu55n4oilV0ix7TvtwkaBkRUjfIM12QyIyo0nrJIQn 0QfEKmHa4cf+cQ41HCzo9XvfXH+F71TySi1/5ecnLmbOsozVwO6kHkUrpCSDd7DCMFH7 +Qd7D8L8rQhjb7w2pEJ6TG4Cb4VBstvOjmCNIyX1Sdxg5bekpOl2yFbqQXAHGU3V7uzM NKMrSoxlU4puoQZG5Tu3YL7pVhAh8HmjkoK3pN/UC3q+s7ThsJRgzENGipsi3hiP3Yy5 ENJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788762521; x=1789367321; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=EPO3XgKtW39x62BjixAoLRnOdq38lit6qHUtJ4zQNAE=; b=RaflNKU6CDmfXlA0KWi2jBUVla9oq8XM7v2On6NHGLHr5bg5/72vvd36aS43mfUc3L j6oLrZE2y4DSbVdIytRwcNAq8Kf+H9L9Lsu7uvLo3PXBwlig29fA+/5g0GUQk6a4TuJz g2bVjJGiCIs5bdl03QDqozDTn3K+KHbqP2oX9j2BdNe7qo/Y2hnkLW8ugqy9ydUnSCNo 3of4bJmwLgdN2OTPFJhAA1srAwv6hdLNgXcqAFYHUu+yB587DLbYxJ04O5WDqewo1T2L /3yTtRiJaA8pyV/WiNh/JuAiu5c+KtChYu5HlMGO/1zQKUVYegqLG0IDl9BkEoGqBTCo FdyA== X-Forwarded-Encrypted: i=1; AKwUvByHWgoDNWU5q+g4VyQhlgU6rD7mTzZF+mdBT6wt2C/SUqd/vcjg7okXvH4tQSA8Liq07uUx7InRc6lJsX8=@vger.kernel.org X-Gm-Message-State: AFuF++kYnIFMhvbNXsaw4GKtmlDPUWF6a5ZZ2Mx0W06Litf4lOdqJYHB HqMPKrc1gFLgXvHmUErkUJh1C643GCqRf/TFnWnKSVulTAc3KiMl5XDZ X-Gm-Gg: AYBFou2yMKXmBoaY5lVooWl/4wm/WKZRUkKvCACa0ryd0JSMwIRGfyVL/sPo4071T/K psYS5ZqvL3GyGgWvi12HEkWubZKeOK3GoyZQ2vbwkJ3UX052UdT+6zzeChmD0NL4iIHz+9QtAiv JQL6MOioFf9fBc/5ymDFJPHp/7qJ80iHvLflWqJM08SASO60DeI72jCAaIo9t9Vq1lNYu2zUD5Z eEhHUGJVQbmkNCrDty0vK4DAFI+gXcnmnWemqBPiae/2UjpggdY2015m9IgOU8gQcuUY2iGWCYQ Xu/Y5Vln2jYX2IYmUwct2R3zMa85ff+FnVdT7bOii6hHPAMtkwtSHS0w3k4gfbuelMimbO326Fi sy0cFq1cZY2lgEmalJhxiu6iYAo+tVCkbZPtBuf/hZc0hDgphKOur2LWrgAl0FrJglToCjlqeyE ZAooWvZTctRHPMdo+WrXvtDQ9YYgVu0ETWE/74+AY57XYUtJaAzAiupwDhp2M6Y59WvWKYPqkKj cORKPfCDxaMuWoqBHMV6hsWNff0z63CetiBj7k7z3tibtXFXoroU0+HKXhXMr/WpDioNqGc X-Received: by 2002:a17:90b:3c48:b0:398:e436:384 with SMTP id 98e67ed59e1d1-39b260d335dmr32816359a91.1.1788762520616; Sun, 06 Sep 2026 23:28:40 -0700 (PDT) Received: from LAPTOP-UUUVNN1I.localdomain ([129.126.57.197]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39b25c974cfsm18978042a91.0.2026.09.06.23.28.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 06 Sep 2026 23:28:40 -0700 (PDT) From: Wei Jie Law <98lawweijie@gmail.com> To: Laurent Pinchart , Hans de Goede , Mauro Carvalho Chehab Cc: Guennadi Liakhovetski , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 2/2] media: uvcvideo: Fix out-of-bounds read in uvc_ctrl_status_event() Date: Mon, 7 Sep 2026 14:28:18 +0800 Message-ID: <20260907062819.2519878-3-98lawweijie@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260907062819.2519878-1-98lawweijie@gmail.com> References: <20260907062819.2519878-1-98lawweijie@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" An out-of-bounds read exists in v6.12.105 and upstream. KASAN crash log: BUG: KASAN: slab-use-after-free in uvc_get_le_value+0x314/0x350 Read of size 1 at addr ffff88802df955e4 by task kworker/0:2/128 Workqueue: events uvc_ctrl_status_event_work uvc_ctrl_status_event+0x128/0x280 uvc_ctrl_status_event_work+0x82/0x240 The buggy address belongs to the object at ffff88802df955e0 which belongs to the cache kmalloc-16 of size 16 uvc_ctrl_add_mapping() validates mapping->offset against the control data buffer, sized from the device's GET_LEN answer. uvc_ctrl_status_event() applies the same offset to the 11 byte bValue field of a control change event, so uvc_get_le_value() reads past the 16 byte struct uvc_status and the value is reported to userspace as a V4L2_EVENT_CTRL change. offset is a u8 bit offset, so the read reaches 24 bytes into the neighbouring objects; KASAN calls it a use-after-free because the neighbour it read had just been freed. Fixes: e5225c820c05 ("media: uvcvideo: Send a control event when a Control = Change interrupt arrives") Cc: stable@vger.kernel.org Signed-off-by: Wei Jie Law <98lawweijie@gmail.com> Assisted-by: Claude:claude-opus-5 --- drivers/media/usb/uvc/uvc_ctrl.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/drivers/media/usb/uvc/uvc_ctrl.c b/drivers/media/usb/uvc/uvc_c= trl.c index 21802f9b1b61..d082bcb8d98d 100644 --- a/drivers/media/usb/uvc/uvc_ctrl.c +++ b/drivers/media/usb/uvc/uvc_ctrl.c @@ -2156,11 +2156,16 @@ void uvc_ctrl_status_event(struct uvc_video_chain *= chain, uvc_ctrl_clear_handle(ctrl); =20 list_for_each_entry(mapping, &ctrl->info.mappings, list) { - s32 value; + s32 value =3D 0; =20 - if (uvc_ctrl_mapping_is_compound(mapping)) - value =3D 0; - else + /* + * The offset is validated against the control size, not + * against the event payload, so a mapping can reach past + * bValue[]. + */ + if (!uvc_ctrl_mapping_is_compound(mapping) && + mapping->offset + mapping->size <=3D + 8 * sizeof_field(struct uvc_status_control, bValue)) value =3D uvc_mapping_get_s32(mapping, UVC_GET_CUR, data); =20 /* --=20 2.43.0