media: mceusb: Fix potential out-of-bounds shift
commit 1b43bad3 upstream. When processing a MCE_RSP_GETPORTSTATUS command, the bit index to set in ir->txports_cabled comes from response data, and isn't validated. As ir->txports_cabled is a u8, nothing should be done if the bit index is greater than 7. Cc: stable@vger.kernel.org Reported-by:<syzbot+ec3b3128c576e109171d@syzkaller.appspotmail.com> Signed-off-by:
James Reynolds <jr@memlen.com> Signed-off-by:
Sean Young <sean@mess.org> Signed-off-by:
Mauro Carvalho Chehab <mchehab+huawei@kernel.org> Signed-off-by:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
parent
8812bed7
Please register or sign in to comment