V4L/DVB (12436): stk-webcam: read buffer overflow
It tested the value of stk_sizes[i].m before checking whether i was in range. Cc: Hans Verkuil <hverkuil@xs4all.nl> Cc: Trent Piepho <xyzzy@speakeasy.org> Signed-off-by: Roel Kluin <roel.kluin@gmail.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Douglas Schilling Landgraf <dougsland@redhat.com> Signed-off-by: Mauro Carvalho Chehab <mchehab@redhat.com>
This commit is contained in:
Родитель
01a5fd6ff3
Коммит
77f2c2db11
|
@ -1050,8 +1050,8 @@ static int stk_setup_format(struct stk_camera *dev)
|
|||
depth = 1;
|
||||
else
|
||||
depth = 2;
|
||||
while (stk_sizes[i].m != dev->vsettings.mode
|
||||
&& i < ARRAY_SIZE(stk_sizes))
|
||||
while (i < ARRAY_SIZE(stk_sizes) &&
|
||||
stk_sizes[i].m != dev->vsettings.mode)
|
||||
i++;
|
||||
if (i == ARRAY_SIZE(stk_sizes)) {
|
||||
STK_ERROR("Something is broken in %s\n", __func__);
|
||||
|
|
Загрузка…
Ссылка в новой задаче