8b7fda1
From a4200b7eb26271108586d3a7cf34a2f16d460e48 Mon Sep 17 00:00:00 2001
8b7fda1
From: Oliver Neukum <oneukum@suse.com>
8b7fda1
Date: Thu, 17 Mar 2016 15:10:47 +0100
8b7fda1
Subject: [PATCH] ims-pcu: sanity check against missing interfaces
8b7fda1
8b7fda1
A malicious device missing interface can make the driver oops.
8b7fda1
Add sanity checking.
8b7fda1
8b7fda1
Signed-off-by: Oliver Neukum <ONeukum@suse.com>
8b7fda1
CC: stable@vger.kernel.org
8b7fda1
---
8b7fda1
 drivers/input/misc/ims-pcu.c | 4 ++++
8b7fda1
 1 file changed, 4 insertions(+)
8b7fda1
8b7fda1
diff --git a/drivers/input/misc/ims-pcu.c b/drivers/input/misc/ims-pcu.c
8b7fda1
index ac1fa5f44580..9c0ea36913b4 100644
8b7fda1
--- a/drivers/input/misc/ims-pcu.c
8b7fda1
+++ b/drivers/input/misc/ims-pcu.c
8b7fda1
@@ -1663,6 +1663,8 @@ static int ims_pcu_parse_cdc_data(struct usb_interface *intf, struct ims_pcu *pc
8b7fda1
 
8b7fda1
 	pcu->ctrl_intf = usb_ifnum_to_if(pcu->udev,
8b7fda1
 					 union_desc->bMasterInterface0);
8b7fda1
+	if (!pcu->ctrl_intf)
8b7fda1
+		return -EINVAL;
8b7fda1
 
8b7fda1
 	alt = pcu->ctrl_intf->cur_altsetting;
8b7fda1
 	pcu->ep_ctrl = &alt->endpoint[0].desc;
8b7fda1
@@ -1670,6 +1672,8 @@ static int ims_pcu_parse_cdc_data(struct usb_interface *intf, struct ims_pcu *pc
8b7fda1
 
8b7fda1
 	pcu->data_intf = usb_ifnum_to_if(pcu->udev,
8b7fda1
 					 union_desc->bSlaveInterface0);
8b7fda1
+	if (!pcu->data_intf)
8b7fda1
+		return -EINVAL;
8b7fda1
 
8b7fda1
 	alt = pcu->data_intf->cur_altsetting;
8b7fda1
 	if (alt->desc.bNumEndpoints != 2) {
8b7fda1
-- 
8b7fda1
2.5.0
8b7fda1