[PATCH] media: cx231xx: drop runt bulk packets to fix heap overflow

From: Shirong Zhao

Date: Mon Oct 05 2026 - 03:27:25 EST


cx231xx_bulk_copy() trusts urb->actual_length and immediately uses it
in three 3-byte operations. A runt packet (actual_length < 3, which a
malicious or faulty device can report, for example as a runt or
zero-length bulk packet) causes a heap out-of-bounds write
(memcpy of 3 bytes into a smaller buffer) and a u32 underflow
(buffer_size - 3 wraps to ~4 billion), turning the following memcpys
into wild reads/writes.

The bulk completion callback invokes this function for every
successful URB without any length check, and ignores the return
value. The sibling isoc path already skips empty packets
(cx231xx_isoc_copy checks buffer_size > 0); the bulk path simply
missed its guard.

Drop packets shorter than the 3-byte header/tail unit before
allocating. Lengths >= 3 keep all three memcpy ranges in bounds,
so 3 is the exact threshold, not a heuristic.

Signed-off-by: Shirong Zhao <shxzhaosr@xxxxxxx>
---
Verified against Linux 7.3-rc6 (a90ee4305c4a5df72c11b31dacfdc76e00fcf78a),
the current mainline master. The file is byte-identical between 7.3-rc5
and 7.3-rc6.
drivers/media/usb/cx231xx/cx231xx-417.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/drivers/media/usb/cx231xx/cx231xx-417.c b/drivers/media/usb/cx231xx/cx231xx-417.c
--- a/drivers/media/usb/cx231xx/cx231xx-417.c
+++ b/drivers/media/usb/cx231xx/cx231xx-417.c
@@ -1347,6 +1347,9 @@
p_buffer = urb->transfer_buffer;
buffer_size = urb->actual_length;

+ if (buffer_size < 3)
+ return 0;
+
buffer = kmalloc(buffer_size, GFP_ATOMIC);
if (!buffer)
return -ENOMEM;