Date: Fri, 24 Jul 2026 15:08:01 +0000 From: Baptiste Daroussin <bapt@FreeBSD.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org Subject: git: 8468152509a0 - main - uvideo: fix step=0 infinite loop and int overflow in fbuf_size Message-ID: <6a637fd1.36047.5626ca1a@gitrepo.freebsd.org>
index | next in thread | raw e-mail
The branch main has been updated by bapt: URL: https://cgit.FreeBSD.org/src/commit/?id=8468152509a0dfd73e69618af2b1d7f9cbd366f7 commit 8468152509a0dfd73e69618af2b1d7f9cbd366f7 Author: Baptiste Daroussin <bapt@FreeBSD.org> AuthorDate: 2026-07-24 14:30:07 +0000 Commit: Baptiste Daroussin <bapt@FreeBSD.org> CommitDate: 2026-07-24 15:07:50 +0000 uvideo: fix step=0 infinite loop and int overflow in fbuf_size Prevent infinite loop in uvideo_vs_negotiation() when a USB camera reports step=0 in its continuous frame interval descriptor. Cast fbuf_size calculation to uint64_t to avoid int overflow for large width/height/bpp combinations. Reported by: emaste --- sys/dev/usb/video/uvideo.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/sys/dev/usb/video/uvideo.c b/sys/dev/usb/video/uvideo.c index 7c7268454ae2..bb52232e153e 100644 --- a/sys/dev/usb/video/uvideo.c +++ b/sys/dev/usb/video/uvideo.c @@ -1744,7 +1744,7 @@ uvideo_vs_parse_desc_frame_buffer_size(struct uvideo_softc *sc, * width * height * bpp since dwMaxVideoFrameBufferSize may be wrong. */ if (desc->bDescriptorSubtype == UDESCSUB_VS_FRAME_UNCOMPRESSED) { - fbuf_size = UGETW(fd->u.uc.wWidth) * + fbuf_size = (uint64_t)UGETW(fd->u.uc.wWidth) * UGETW(fd->u.uc.wHeight) * sc->sc_fmtgrp[fmtidx].format->u.uc.bBitsPerPixel / NBBY; } else @@ -2037,6 +2037,8 @@ uvideo_vs_negotiation(struct uvideo_softc *sc, int commit) else if (frame_ival >= max) frame_ival = max; else { + if (step == 0) + step = 1; for (i = min; i + step / 2 < frame_ival; i += step)home | help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6a637fd1.36047.5626ca1a>
