mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-28 02:53:16 -04:00
Input: synaptics-rmi4 - block s_input when F54 queue is busy
Changing the input (diagnostic report type) mid-stream changes the
report size. Since V4L2 buffers are allocated based on the size at
stream start, changing the input while streaming could lead to a
heap buffer overflow if the new size is larger than the allocated
buffers.
Prevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue
is busy (streaming).
Fixes: 3a762dbd53 ("[media] Input: synaptics-rmi4 - add support for F54 diagnostics")
Cc: stable@vger.kernel.org
Assisted-by: Antigravity:gemini-3.5-flash
Reviewed-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Link: https://patch.msgid.link/20260626051802.4033172-5-dmitry.torokhov@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
This commit is contained in:
@@ -445,7 +445,12 @@ static int rmi_f54_set_input(struct f54_data *f54, unsigned int i)
|
||||
|
||||
static int rmi_f54_vidioc_s_input(struct file *file, void *priv, unsigned int i)
|
||||
{
|
||||
return rmi_f54_set_input(video_drvdata(file), i);
|
||||
struct f54_data *f54 = video_drvdata(file);
|
||||
|
||||
if (vb2_is_busy(&f54->queue))
|
||||
return -EBUSY;
|
||||
|
||||
return rmi_f54_set_input(f54, i);
|
||||
}
|
||||
|
||||
static int rmi_f54_vidioc_g_input(struct file *file, void *priv,
|
||||
|
||||
Reference in New Issue
Block a user