From 33dc3d7128456d51b1fe6228096e6b714a3e900b Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Wed, 27 Apr 2016 09:01:16 +1000 Subject: Prevent buffer overrun accessing btn_labels We go up to BTN_JOYSTICK, hence group can have a value of up to including 15. The actual btn_labels only has 6 elements though. Found by coverity. Signed-off-by: Peter Hutterer --- src/evdev.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/evdev.c b/src/evdev.c index 0fcb0bb..2c88343 100644 --- a/src/evdev.c +++ b/src/evdev.c @@ -2790,6 +2790,9 @@ static void EvdevInitButtonLabels(EvdevPtr pEvdev, int natoms, Atom *atoms) int group = (button % 0x100)/16; int idx = button - ((button/16) * 16); + if (group >= ArrayLength(btn_labels)) + break; + if (!libevdev_has_event_code(pEvdev->dev, EV_KEY, button)) continue; -- cgit v1.2.1