Re: [PATCH] media: uvcvideo: Fix buffer overflow in uvc_mapping_get_menu_value()

From: Laurent Pinchart

Date: Mon Sep 28 2026 - 16:31:22 EST


On Fri, Sep 18, 2026 at 03:20:25PM +0300, Dan Carpenter wrote:
> The "idx" value is a user controlled u32 so we have to bounds check it
> before calling test_bit() to avoid reading beyond the end of the bitmap.
>
> Fixes: 4e15c535659b ("media: uvcvideo: Support any size for mapping get/set")
> Signed-off-by: Dan Carpenter <error27@xxxxxxxxx>

What's the status of this patch ? The issue is a false positive, do you
still think there's value in this redundant test ?

> ---
> drivers/media/usb/uvc/uvc_ctrl.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/media/usb/uvc/uvc_ctrl.c b/drivers/media/usb/uvc/uvc_ctrl.c
> index 3ca108b83f1d..f157ed99be4e 100644
> --- a/drivers/media/usb/uvc/uvc_ctrl.c
> +++ b/drivers/media/usb/uvc/uvc_ctrl.c
> @@ -538,7 +538,7 @@ static void uvc_mapping_set_s32(struct uvc_control_mapping *mapping,
> static int uvc_mapping_get_menu_value(const struct uvc_control_mapping *mapping,
> u32 idx)
> {
> - if (!test_bit(idx, &mapping->menu_mask))
> + if (idx >= BITS_PER_LONG || !test_bit(idx, &mapping->menu_mask))
> return -EINVAL;
>
> if (mapping->menu_mapping)

--
Regards,

Laurent Pinchart