mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
Input: synaptics-rmi4 - block s_input when F54 queue is busy
commitfbfd76746aupstream. Changing the input (diagnostic report type) mid-stream changes the report size. Since V4L2 buffers are allocated based on the size at stream start, changing the input while streaming could lead to a heap buffer overflow if the new size is larger than the allocated buffers. Prevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue is busy (streaming). Fixes:3a762dbd53("[media] Input: synaptics-rmi4 - add support for F54 diagnostics") Cc: stable@vger.kernel.org Assisted-by: Antigravity:gemini-3.5-flash Reviewed-by: Hans Verkuil <hverkuil+cisco@kernel.org> Link: https://patch.msgid.link/20260626051802.4033172-5-dmitry.torokhov@gmail.com Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
12be3c6ca9
commit
1d718f1461
@@ -447,7 +447,12 @@ static int rmi_f54_set_input(struct f54_data *f54, unsigned int i)
|
||||
|
||||
static int rmi_f54_vidioc_s_input(struct file *file, void *priv, unsigned int i)
|
||||
{
|
||||
return rmi_f54_set_input(video_drvdata(file), i);
|
||||
struct f54_data *f54 = video_drvdata(file);
|
||||
|
||||
if (vb2_is_busy(&f54->queue))
|
||||
return -EBUSY;
|
||||
|
||||
return rmi_f54_set_input(f54, i);
|
||||
}
|
||||
|
||||
static int rmi_f54_vidioc_g_input(struct file *file, void *priv,
|
||||
|
||||
Reference in New Issue
Block a user