Re: [PATCH] media: uvcvideo: Fix buffer overflow in uvc_mapping_get_menu_value()

From: Ricardo Ribalda

Date: Thu Oct 08 2026 - 02:47:55 EST


Hi all



On Tue, 29 Sept 2026 at 07:30, Dan Carpenter <error27@xxxxxxxxx> wrote:
>
> On Mon, Sep 28, 2026 at 11:31:05PM +0300, Laurent Pinchart wrote:
> > On Fri, Sep 18, 2026 at 03:20:25PM +0300, Dan Carpenter wrote:
> > > The "idx" value is a user controlled u32 so we have to bounds check it
> > > before calling test_bit() to avoid reading beyond the end of the bitmap.
> > >
> > > Fixes: 4e15c535659b ("media: uvcvideo: Support any size for mapping get/set")
> > > Signed-off-by: Dan Carpenter <error27@xxxxxxxxx>
> >
> > What's the status of this patch ? The issue is a false positive, do you
> > still think there's value in this redundant test ?
> >
>
> No, it's a false positive.
>
> With how Smatch works, I don't have an easy way to silence it in Smatch,
> but I'm going to publish my AI skills file for reviewing static checker
> warnings. Also I've started writing a new tool to help filter false
> positives.

Even if it is a false positive, I think it is a good addition, it
makes the code more robust.

Do you mind if I make a respin of it with my comments (keeping you as author)?
(Or if you want to send a v2 that would be awesome as well :) )

Thanks!

>
> regards,
> dan carpenter
>


--
Ricardo Ribalda