Skip to content

Commit

Permalink
Input: cm109 - validate number of endpoints before using them
Browse files Browse the repository at this point in the history
Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: c04148f ("Input: add driver for USB VoIP phones with CM109...")
Signed-off-by: Johan Hovold <johan@kernel.org>
Cc: stable@vger.kernel.org	# 2.6.28
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
  • Loading branch information
Johan Hovold authored and Dmitry Torokhov committed Mar 16, 2017
1 parent 59cf8be commit ac2ee9b
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions drivers/input/misc/cm109.c
Original file line number Diff line number Diff line change
Expand Up @@ -700,6 +700,10 @@ static int cm109_usb_probe(struct usb_interface *intf,
int error = -ENOMEM;

interface = intf->cur_altsetting;

if (interface->desc.bNumEndpoints < 1)
return -ENODEV;

endpoint = &interface->endpoint[0].desc;

if (!usb_endpoint_is_int_in(endpoint))
Expand Down

0 comments on commit ac2ee9b

Please sign in to comment.