| From: Johan Hovold <johan@kernel.org> |
| Date: Thu, 16 Mar 2017 11:35:12 -0700 |
| Subject: Input: cm109 - validate number of endpoints before using them |
| |
| commit ac2ee9ba953afe88f7a673e1c0c839227b1d7891 upstream. |
| |
| Make sure to check the number of endpoints to avoid dereferencing a |
| NULL-pointer should a malicious device lack endpoints. |
| |
| Fixes: c04148f915e5 ("Input: add driver for USB VoIP phones with CM109...") |
| Signed-off-by: Johan Hovold <johan@kernel.org> |
| Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com> |
| Signed-off-by: Ben Hutchings <ben@decadent.org.uk> |
| --- |
| drivers/input/misc/cm109.c | 4 ++++ |
| 1 file changed, 4 insertions(+) |
| |
| --- a/drivers/input/misc/cm109.c |
| +++ b/drivers/input/misc/cm109.c |
| @@ -675,6 +675,10 @@ static int cm109_usb_probe(struct usb_in |
| int error = -ENOMEM; |
| |
| interface = intf->cur_altsetting; |
| + |
| + if (interface->desc.bNumEndpoints < 1) |
| + return -ENODEV; |
| + |
| endpoint = &interface->endpoint[0].desc; |
| |
| if (!usb_endpoint_is_int_in(endpoint)) |