[PATCH v2 0/2] media: uvcvideo: Do not read beyond the uvc_status urb

From: Ricardo Ribalda

Date: Fri Oct 02 2026 - 07:21:24 EST


When we receive an interrupt status with a control change, verify that
the urb has enough data before we read it.

While fixing it we figured out that one of the mappings was using an
invalid size. It was working fine because it used a custom map function,
but now we rely on that value.

Signed-off-by: Ricardo Ribalda <ribalda@xxxxxxxxxxxx>
---
Changes in v2:
- Use wMaxPacketSize for the urb size (Thanks Laurent).
- New patch to set the proper size of V4L2_CID_ZOOM_CONTINUOUS.
- Link to v1: https://lore.kernel.org/r/20260813-uvc-status-11-v1-1-2cf43e9590b0@xxxxxxxxxxxx

---
Ricardo Ribalda (2):
media: uvcvideo: Introduce scattered field for uvc_control_mapping
media: uvcvideo: Do not read beyond the uvc_status_control memory

drivers/media/usb/uvc/uvc_ctrl.c | 18 +++++++++++++-----
drivers/media/usb/uvc/uvc_driver.c | 2 +-
drivers/media/usb/uvc/uvc_status.c | 18 +++++++++++++-----
drivers/media/usb/uvc/uvcvideo.h | 15 ++++++++++++---
4 files changed, 39 insertions(+), 14 deletions(-)
---
base-commit: 7fa44c2c123c17c4a3856ffac5e384409267cced
change-id: 20260813-uvc-status-11-99b9e27a8ea9

Best regards,
--
Ricardo Ribalda <ribalda@xxxxxxxxxxxx>