Re: [PATCH] media: uvcvideo: Fix buffer overflow in uvc_mapping_get_menu_value()

From: Dan Carpenter

Date: Tue Sep 29 2026 - 01:30:06 EST


On Mon, Sep 28, 2026 at 11:31:05PM +0300, Laurent Pinchart wrote:
> On Fri, Sep 18, 2026 at 03:20:25PM +0300, Dan Carpenter wrote:
> > The "idx" value is a user controlled u32 so we have to bounds check it
> > before calling test_bit() to avoid reading beyond the end of the bitmap.
> >
> > Fixes: 4e15c535659b ("media: uvcvideo: Support any size for mapping get/set")
> > Signed-off-by: Dan Carpenter <error27@xxxxxxxxx>
>
> What's the status of this patch ? The issue is a false positive, do you
> still think there's value in this redundant test ?
>

No, it's a false positive.

With how Smatch works, I don't have an easy way to silence it in Smatch,
but I'm going to publish my AI skills file for reviewing static checker
warnings. Also I've started writing a new tool to help filter false
positives.

regards,
dan carpenter