Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 8 Jun 2019 09:34:02 +0000 (UTC)
From:      Hans Petter Selasky <hselasky@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org
Subject:   svn commit: r348797 - head/lib/libusb
Message-ID:  <201906080934.x589Y2Cv080407@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: hselasky
Date: Sat Jun  8 09:34:02 2019
New Revision: 348797
URL: https://svnweb.freebsd.org/changeset/base/348797

Log:
  Fix for reading the configuration descriptor in libusb. Catch invalid
  configuration descriptor reads early on to avoid issues with devices
  that don't check for a valid USB configuration read request.
  
  Submitted by:	takahiro.kurosawa@gmail.com
  PR:		238412
  MFC after:	3 days

Modified:
  head/lib/libusb/libusb20.c

Modified: head/lib/libusb/libusb20.c
==============================================================================
--- head/lib/libusb/libusb20.c	Sat Jun  8 08:25:43 2019	(r348796)
+++ head/lib/libusb/libusb20.c	Sat Jun  8 09:34:02 2019	(r348797)
@@ -955,6 +955,14 @@ libusb20_dev_alloc_config(struct libusb20_device *pdev
 	uint8_t do_close;
 	int error;
 
+	/*
+	 * Catch invalid configuration descriptor reads early on to
+	 * avoid issues with devices that don't check for a valid USB
+	 * configuration read request.
+	 */
+	if (configIndex >= pdev->ddesc.bNumConfigurations)
+		return (NULL);
+
 	if (!pdev->is_opened) {
 		error = libusb20_dev_open(pdev, 0);
 		if (error) {



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201906080934.x589Y2Cv080407>