21aa01da9d
commit bcfcb7f9b480dd0be8f0df2df17340ca92a03b98 upstream.
The driver was checking the number of endpoints of the first alternate
setting instead of the current one, something which could be used by a
malicious device (or USB descriptor fuzzer) to trigger a NULL-pointer
dereference.
Fixes:
|
||
---|---|---|
.. | ||
Kconfig | ||
Makefile | ||
acecad.c | ||
aiptek.c | ||
gtco.c | ||
hanwang.c | ||
kbtab.c | ||
pegasus_notetaker.c | ||
wacom_serial4.c |