| From 58f40a38ee8f6f73afdc6aaa94cd26b3c8f1522d Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Thu, 5 Jan 2023 22:17:04 -0800 |
| Subject: media: uvcvideo: Silence memcpy() run-time false positive warnings |
| |
| From: Kees Cook <keescook@chromium.org> |
| |
| [ Upstream commit b839212988575c701aab4d3d9ca15e44c87e383c ] |
| |
| The memcpy() in uvc_video_decode_meta() intentionally copies across the |
| length and flags members and into the trailing buf flexible array. |
| Split the copy so that the compiler can better reason about (the lack |
| of) buffer overflows here. Avoid the run-time false positive warning: |
| |
| memcpy: detected field-spanning write (size 12) of single field "&meta->length" at drivers/media/usb/uvc/uvc_video.c:1355 (size 1) |
| |
| Additionally fix a typo in the documentation for struct uvc_meta_buf. |
| |
| Reported-by: ionut_n2001@yahoo.com |
| Link: https://bugzilla.kernel.org/show_bug.cgi?id=216810 |
| Signed-off-by: Kees Cook <keescook@chromium.org> |
| Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com> |
| Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/media/usb/uvc/uvc_video.c | 4 +++- |
| include/uapi/linux/uvcvideo.h | 2 +- |
| 2 files changed, 4 insertions(+), 2 deletions(-) |
| |
| diff --git a/drivers/media/usb/uvc/uvc_video.c b/drivers/media/usb/uvc/uvc_video.c |
| index d5a4e967883c5..03dfe96bcebac 100644 |
| --- a/drivers/media/usb/uvc/uvc_video.c |
| +++ b/drivers/media/usb/uvc/uvc_video.c |
| @@ -1308,7 +1308,9 @@ static void uvc_video_decode_meta(struct uvc_streaming *stream, |
| if (has_scr) |
| memcpy(stream->clock.last_scr, scr, 6); |
| |
| - memcpy(&meta->length, mem, length); |
| + meta->length = mem[0]; |
| + meta->flags = mem[1]; |
| + memcpy(meta->buf, &mem[2], length - 2); |
| meta_buf->bytesused += length + sizeof(meta->ns) + sizeof(meta->sof); |
| |
| uvc_trace(UVC_TRACE_FRAME, |
| diff --git a/include/uapi/linux/uvcvideo.h b/include/uapi/linux/uvcvideo.h |
| index f80f05b3c423f..2140923661934 100644 |
| --- a/include/uapi/linux/uvcvideo.h |
| +++ b/include/uapi/linux/uvcvideo.h |
| @@ -86,7 +86,7 @@ struct uvc_xu_control_query { |
| * struct. The first two fields are added by the driver, they can be used for |
| * clock synchronisation. The rest is an exact copy of a UVC payload header. |
| * Only complete objects with complete buffers are included. Therefore it's |
| - * always sizeof(meta->ts) + sizeof(meta->sof) + meta->length bytes large. |
| + * always sizeof(meta->ns) + sizeof(meta->sof) + meta->length bytes large. |
| */ |
| struct uvc_meta_buf { |
| __u64 ns; |
| -- |
| 2.39.2 |
| |