mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 00/10] HID: validate short reports in raw_event callbacks
@ 2026-09-24 14:13 Jiale Yao
  2026-09-24 14:13 ` [PATCH 01/10] HID: alps: reject short input reports Jiale Yao
                   ` (9 more replies)
  0 siblings, 10 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao

__hid_input_report() calls a driver's raw_event callback before
hid_report_raw_event() validates the received length against the report
descriptor.  A raw_event callback must therefore validate size before
accessing fixed offsets or casting data to a protocol structure.

Ten HID drivers currently access fields beyond the received length when a
device supplies a truncated report.  Add protocol-specific checks before
those accesses.  The patches are independent and each changes one driver.

The mcp2200, pxrc, and zydacron cases were reproduced with a fake HID
transport under KASAN.  Their individual commit messages include the
relevant reports.  The remaining paths were verified by following their
fixed-offset accesses from raw_event.

This follows the local raw_event size check added to hid-asus by commit
47669bec44fe ("HID: asus: refactor the two workqueues and init sequence").

Jiale Yao (10):
  HID: alps: reject short input reports
  HID: cougar: reject short special-key reports
  HID: cp2112: validate response report lengths
  HID: elo: reject short touchscreen reports
  HID: logitech-dj: validate unnumbered keyboard reports
  HID: mcp2200: validate READ_ALL response length
  HID: mcp2221: validate response report length
  HID: prodikeys: validate fixed-format MIDI reports
  HID: pxrc: reject short input reports
  HID: zydacron: validate key report length

 drivers/hid/hid-alps.c        | 8 +++++++-
 drivers/hid/hid-cougar.c      | 3 +++
 drivers/hid/hid-cp2112.c      | 9 ++++++++-
 drivers/hid/hid-elo.c         | 3 +++
 drivers/hid/hid-logitech-dj.c | 3 +++
 drivers/hid/hid-mcp2200.c     | 5 +++++
 drivers/hid/hid-mcp2221.c     | 2 +-
 drivers/hid/hid-prodikeys.c   | 7 ++++++-
 drivers/hid/hid-pxrc.c        | 3 +++
 drivers/hid/hid-zydacron.c    | 3 +++
 10 files changed, 42 insertions(+), 4 deletions(-)

-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 01/10] HID: alps: reject short input reports
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 02/10] HID: cougar: reject short special-key reports Jiale Yao
                   ` (8 subsequent siblings)
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes a driver's raw_event callback before validating the
report length.  Both ALPS input parsers therefore need to validate size
before accessing their fixed-format reports.

t4_raw_event() casts the buffer to struct t4_input_report and reads its
contacts and button.  u1_raw_event() reads five bytes per configured finger
starting at offset three, or six bytes for a stick report.  A short report
can make either parser read beyond the valid data.

Reject reports that do not contain all fields used by the selected parser.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 2562756dde55 ("HID: add Alps I2C HID Touchpad-Stick support")
Fixes: 73196ebe134d ("HID: alps: add support for Alps T4 Touchpad device")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-alps.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/hid/hid-alps.c b/drivers/hid/hid-alps.c
index 67179e3fe39b..b1950aff6ad4 100644
--- a/drivers/hid/hid-alps.c
+++ b/drivers/hid/hid-alps.c
@@ -322,7 +322,7 @@ static int t4_raw_event(struct alps_dev *hdata, u8 *data, int size)
 	int i;
 	struct t4_input_report *p_report = (struct t4_input_report *)data;
 
-	if (!data)
+	if (size < sizeof(*p_report))
 		return 0;
 	for (i = 0; i < hdata->max_fingers; i++) {
 		x = p_report->contact[i].x_hi << 8 | p_report->contact[i].x_lo;
@@ -370,6 +370,9 @@ static int u1_raw_event(struct alps_dev *hdata, u8 *data, int size)
 		break;
 	case U1_ABSOLUTE_REPORT_ID:
 	case U1_ABSOLUTE_REPORT_ID_SECD:
+		if (size < 3 + hdata->max_fingers * 5)
+			return 0;
+
 		for (i = 0; i < hdata->max_fingers; i++) {
 			u8 *contact = &data[i * 5];
 
@@ -407,6 +410,9 @@ static int u1_raw_event(struct alps_dev *hdata, u8 *data, int size)
 		return 1;
 
 	case U1_SP_ABSOLUTE_REPORT_ID:
+		if (size < 6)
+			return 0;
+
 		sp_x = get_unaligned_le16(data+2);
 		sp_y = get_unaligned_le16(data+4);
 
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 02/10] HID: cougar: reject short special-key reports
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
  2026-09-24 14:13 ` [PATCH 01/10] HID: alps: reject short input reports Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 03/10] HID: cp2112: validate response report lengths Jiale Yao
                   ` (7 subsequent siblings)
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  cougar_raw_event() reads the key code and action from offsets one
and two without checking that those bytes are present.  A short report on
the special interface can therefore cause an out-of-bounds read.

Consume reports that do not contain the action field before accessing the
fixed offsets, consistent with the callback's handling of other reports on
the special interface.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: b8e759b8f6da ("HID: cougar: Add support for the Cougar 500k Gaming Keyboard")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-cougar.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/hid/hid-cougar.c b/drivers/hid/hid-cougar.c
index ad027c45f162..7156658166f5 100644
--- a/drivers/hid/hid-cougar.c
+++ b/drivers/hid/hid-cougar.c
@@ -270,6 +270,9 @@ static int cougar_raw_event(struct hid_device *hdev, struct hid_report *report,
 	if (!shared->enabled || !shared->input)
 		return -EPERM;
 
+	if (size <= COUGAR_FIELD_ACTION)
+		return -EPERM;
+
 	code = data[COUGAR_FIELD_CODE];
 	action = data[COUGAR_FIELD_ACTION];
 	for (i = 0; cougar_mapping[i][0]; i++) {
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 03/10] HID: cp2112: validate response report lengths
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
  2026-09-24 14:13 ` [PATCH 01/10] HID: alps: reject short input reports Jiale Yao
  2026-09-24 14:13 ` [PATCH 02/10] HID: cougar: reject short special-key reports Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 04/10] HID: elo: reject short touchscreen reports Jiale Yao
                   ` (6 subsequent siblings)
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  cp2112_raw_event() reads every field of a transfer status response
without checking size.  For a data response, it reads the length at offset
two and copies that many bytes from offset three, again without ensuring
that the input report contains them.

Require a complete transfer status structure.  For data responses, first
require the header and then ensure the clamped payload length fits in the
received report before copying it.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: e932d8178667 ("HID: add hid-cp2112 driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-cp2112.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/hid/hid-cp2112.c b/drivers/hid/hid-cp2112.c
index 04379db93571..6b938f75e72f 100644
--- a/drivers/hid/hid-cp2112.c
+++ b/drivers/hid/hid-cp2112.c
@@ -1430,6 +1430,9 @@ static int cp2112_raw_event(struct hid_device *hdev, struct hid_report *report,
 
 	switch (data[0]) {
 	case CP2112_TRANSFER_STATUS_RESPONSE:
+		if (size < sizeof(*xfer))
+			return 0;
+
 		hid_dbg(hdev, "xfer status: %02x %02x %04x %04x\n",
 			xfer->status0, xfer->status1,
 			be16_to_cpu(xfer->retries), be16_to_cpu(xfer->length));
@@ -1463,11 +1466,16 @@ static int cp2112_raw_event(struct hid_device *hdev, struct hid_report *report,
 		atomic_set(&dev->xfer_avail, 1);
 		break;
 	case CP2112_DATA_READ_RESPONSE:
+		if (size < 3)
+			return 0;
+
 		hid_dbg(hdev, "read response: %02x %02x\n", data[1], data[2]);
 
 		dev->read_length = data[2];
 		if (dev->read_length > sizeof(dev->read_data))
 			dev->read_length = sizeof(dev->read_data);
+		if (dev->read_length > size - 3)
+			return 0;
 
 		memcpy(dev->read_data, &data[3], dev->read_length);
 		atomic_set(&dev->read_avail, 1);
@@ -1494,4 +1502,3 @@ module_hid_driver(cp2112_driver);
 MODULE_DESCRIPTION("Silicon Labs HID USB to SMBus master bridge");
 MODULE_AUTHOR("David Barksdale <dbarksdale@uplogix.com>");
 MODULE_LICENSE("GPL");
-
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 04/10] HID: elo: reject short touchscreen reports
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
                   ` (2 preceding siblings ...)
  2026-09-24 14:13 ` [PATCH 03/10] HID: cp2112: validate response report lengths Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 05/10] HID: logitech-dj: validate unnumbered keyboard reports Jiale Yao
                   ` (5 subsequent siblings)
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  elo_raw_event() only checks the first-byte packet marker before
elo_process_data() reads coordinates, flags, and pressure through offset
seven.  A truncated packet beginning with the expected marker can therefore
cause an out-of-bounds read.

Require the complete eight-byte SmartSet packet before parsing it.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: d23efc19478a ("HID: add driver for ELO 4000/4500")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-elo.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/hid/hid-elo.c b/drivers/hid/hid-elo.c
index b8f5f3eb53a4..86e8729e1975 100644
--- a/drivers/hid/hid-elo.c
+++ b/drivers/hid/hid-elo.c
@@ -85,6 +85,9 @@ static int elo_raw_event(struct hid_device *hdev, struct hid_report *report,
 	if (!(hdev->claimed & HID_CLAIMED_INPUT) || list_empty(&hdev->inputs))
 		return 0;
 
+	if (size < ELO_SMARTSET_PACKET_SIZE)
+		return 0;
+
 	hidinput = list_first_entry(&hdev->inputs, struct hid_input, list);
 
 	switch (report->id) {
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 05/10] HID: logitech-dj: validate unnumbered keyboard reports
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
                   ` (3 preceding siblings ...)
  2026-09-24 14:13 ` [PATCH 04/10] HID: elo: reject short touchscreen reports Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 06/10] HID: mcp2200: validate READ_ALL response length Jiale Yao
                   ` (4 subsequent siblings)
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  For an unnumbered keyboard report, logi_dj_raw_event() uses the
second byte as temporary storage while prepending a report ID.  A one-byte
report therefore makes both the initial write and the later restoration
access data beyond the received report.

Reject unnumbered keyboard reports that do not provide the temporary byte.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 74808f9115ce ("HID: logitech-dj: add support for non unifying receivers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-logitech-dj.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/hid/hid-logitech-dj.c b/drivers/hid/hid-logitech-dj.c
index 1d619d2345e1..ce5e0f7218b8 100644
--- a/drivers/hid/hid-logitech-dj.c
+++ b/drivers/hid/hid-logitech-dj.c
@@ -1813,6 +1813,9 @@ static int logi_dj_raw_event(struct hid_device *hdev,
 	if (!hdev->report_enum[HID_INPUT_REPORT].numbered) {
 
 		if (djrcv_dev->unnumbered_application == HID_GD_KEYBOARD) {
+			if (size < 2)
+				return false;
+
 			/*
 			 * For the keyboard, we can reuse the same report by
 			 * using the second byte which is constant in the USB
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 06/10] HID: mcp2200: validate READ_ALL response length
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
                   ` (4 preceding siblings ...)
  2026-09-24 14:13 ` [PATCH 05/10] HID: logitech-dj: validate unnumbered keyboard reports Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 07/10] HID: mcp2221: validate response report length Jiale Yao
                   ` (3 subsequent siblings)
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  mcp2200_raw_event() casts a READ_ALL response to struct
mcp_read_all_resp and reads fields through offset ten without checking that
the response contains the structure.

A one-byte READ_ALL response reproduced the issue under KASAN:

  BUG: KASAN: slab-out-of-bounds in mcp2200_raw_event+0x24b/0x3a0
  Read of size 1 by task hidtrigger/89
  Call Trace:
   mcp2200_raw_event+0x24b/0x3a0
   kasan_report+0x139/0x170

Reject an incomplete READ_ALL response with a protocol error before reading
its fields.  The common completion path then wakes the command waiter with
the error instead of leaving it to time out.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 740329d7120f ("HID: mcp2200: added driver for GPIOs of MCP2200")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-mcp2200.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/hid/hid-mcp2200.c b/drivers/hid/hid-mcp2200.c
index dafdd5b4a079..c6fd5fb5d578 100644
--- a/drivers/hid/hid-mcp2200.c
+++ b/drivers/hid/hid-mcp2200.c
@@ -301,6 +301,11 @@ static int mcp2200_raw_event(struct hid_device *hdev, struct hid_report *report,
 
 	switch (data[0]) {
 	case READ_ALL:
+		if (size < sizeof(*all_resp)) {
+			mcp->status = -EPROTO;
+			break;
+		}
+
 		all_resp = (struct mcp_read_all_resp *) data;
 		mcp->status = 0;
 		mcp->gpio_inval = all_resp->io_port_val_bmap;
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 07/10] HID: mcp2221: validate response report length
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
                   ` (5 preceding siblings ...)
  2026-09-24 14:13 ` [PATCH 06/10] HID: mcp2200: validate READ_ALL response length Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 08/10] HID: prodikeys: validate fixed-format MIDI reports Jiale Yao
                   ` (2 subsequent siblings)
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

MCP2221 responses are 64-byte reports, but mcp2221_raw_event() currently
accepts any report of at least four bytes.  Several response handlers read
far beyond that minimum.  In particular, the I2C status response reads
offset 20 and copies ADC samples starting at offset 50.  Other GPIO, SRAM,
and flash response handlers also access fixed offsets beyond byte three.

The HID core invokes raw_event callbacks before validating the report
length, so a truncated response can cause an out-of-bounds read.  Require a
complete protocol report before dispatching any response handler.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 67a95c21463d ("HID: mcp2221: add usb to i2c-smbus host bridge")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-mcp2221.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/hid/hid-mcp2221.c b/drivers/hid/hid-mcp2221.c
index d52ce3531ab7..db0b15622c39 100644
--- a/drivers/hid/hid-mcp2221.c
+++ b/drivers/hid/hid-mcp2221.c
@@ -865,7 +865,7 @@ static int mcp2221_raw_event(struct hid_device *hdev,
 	u8 *buf;
 	struct mcp2221 *mcp = hid_get_drvdata(hdev);
 
-	if (size < 4)
+	if (size < sizeof(mcp->txbuf))
 		return 0;
 
 	switch (data[0]) {
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 08/10] HID: prodikeys: validate fixed-format MIDI reports
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
                   ` (6 preceding siblings ...)
  2026-09-24 14:13 ` [PATCH 07/10] HID: mcp2221: validate response report length Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 09/10] HID: pxrc: reject short input reports Jiale Yao
  2026-09-24 14:13 ` [PATCH 10/10] HID: zydacron: validate key report length Jiale Yao
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  Prodikeys reports 0x01 and 0x04 are passed to handlers that always
read bytes one through three, regardless of the supplied size.  A truncated
report can therefore cause an out-of-bounds read.

Require four bytes for the two fixed-format reports.  Keep report 0x03 on
its existing variable-length path, which derives the number of note pairs
from size and only accesses complete pairs.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 3a370ca1dcf8 ("HID: Prodikeys PC-MIDI HID Driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-prodikeys.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/hid/hid-prodikeys.c b/drivers/hid/hid-prodikeys.c
index fba01e4fcab1..bf5add40d3e1 100644
--- a/drivers/hid/hid-prodikeys.c
+++ b/drivers/hid/hid-prodikeys.c
@@ -772,8 +772,13 @@ static int pk_raw_event(struct hid_device *hdev, struct hid_report *report,
 		if (report->id == data[0])
 			switch (report->id) {
 			case 0x01: /* midi keys (qwerty)*/
-			case 0x03: /* midi keyboard (musical)*/
 			case 0x04: /* extra/midi keys (qwerty)*/
+				if (size < 4)
+					break;
+				ret = pcmidi_handle_report(pm, report->id,
+							   data, size);
+				break;
+			case 0x03: /* midi keyboard (musical)*/
 				ret = pcmidi_handle_report(pm,
 						report->id, data, size);
 				break;
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 09/10] HID: pxrc: reject short input reports
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
                   ` (7 preceding siblings ...)
  2026-09-24 14:13 ` [PATCH 08/10] HID: prodikeys: validate fixed-format MIDI reports Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  2026-09-24 14:13 ` [PATCH 10/10] HID: zydacron: validate key report length Jiale Yao
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  pxrc_raw_event() reads byte seven and writes bytes one and seven
without checking that the report contains those bytes.

A one-byte input report reproduced the first invalid access under KASAN:

  BUG: KASAN: slab-out-of-bounds in pxrc_raw_event+0x161/0x260
  Read of size 1 by task hidtrigger/90
  Call Trace:
   pxrc_raw_event+0x161/0x260
   kasan_report+0x139/0x170

Require all eight bytes before reading or rewriting the report.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: acc3e34613da ("HID: Add driver for PhoenixRC Flight Controller")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-pxrc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/hid/hid-pxrc.c b/drivers/hid/hid-pxrc.c
index 71fe0c06ddcd..e3755d8b85c2 100644
--- a/drivers/hid/hid-pxrc.c
+++ b/drivers/hid/hid-pxrc.c
@@ -55,6 +55,9 @@ static int pxrc_raw_event(struct hid_device *hdev, struct hid_report *report,
 {
 	struct pxrc_priv *priv = hid_get_drvdata(hdev);
 
+	if (size < 8)
+		return 0;
+
 	if (priv->alternate)
 		priv->slider = data[7];
 	else
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 10/10] HID: zydacron: validate key report length
  2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
                   ` (8 preceding siblings ...)
  2026-09-24 14:13 ` [PATCH 09/10] HID: pxrc: reject short input reports Jiale Yao
@ 2026-09-24 14:13 ` Jiale Yao
  9 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:13 UTC (permalink / raw)
  To: Jiri Kosina, Benjamin Tissoires, Masaki Ota, Daniel M. Lambea,
	David Barksdale, linux-input, linux-kernel
  Cc: Jiale Yao, stable

The HID core invokes raw_event callbacks before validating the report
length.  zc_raw_event() verifies the report ID in byte zero and then reads
the key code from byte one for report IDs 0x02 and 0x03 without checking
that the second byte is present.

A one-byte report reproduced the issue under KASAN:

  BUG: KASAN: slab-out-of-bounds in zc_raw_event+0x54c/0x580
  Read of size 1 by task hidtrigger/93
  Call Trace:
   zc_raw_event+0x54c/0x580
   __hid_input_report+0x2ef/0x3a0
   inject_store+0x479/0x490 [faketrans]

Require both the report ID and key code before processing the report.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: d0742abaa1c3 ("HID: add omitted hid-zydacron.c file")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-zydacron.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/hid/hid-zydacron.c b/drivers/hid/hid-zydacron.c
index 1aae80f848f5..02de153d5628 100644
--- a/drivers/hid/hid-zydacron.c
+++ b/drivers/hid/hid-zydacron.c
@@ -114,6 +114,9 @@ static int zc_raw_event(struct hid_device *hdev, struct hid_report *report,
 	unsigned key;
 	unsigned short index;
 
+	if (size < 2)
+		return 0;
+
 	if (report->id == data[0] && (hdev->claimed & HID_CLAIMED_INPUT)) {
 
 		/* break keys */
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 07/10] HID: mcp2221: validate response report length
  2026-09-24 14:44 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
@ 2026-09-24 14:44 ` Jiale Yao
  0 siblings, 0 replies; 12+ messages in thread
From: Jiale Yao @ 2026-09-24 14:44 UTC (permalink / raw)
  To: Rishi Gupta, Jiri Kosina, Benjamin Tissoires, linux-i2c,
	linux-input, linux-kernel
  Cc: Jiale Yao, stable

MCP2221 responses are 64-byte reports, but mcp2221_raw_event() currently
accepts any report of at least four bytes.  Several response handlers read
far beyond that minimum.  In particular, the I2C status response reads
offset 20 and copies ADC samples starting at offset 50.  Other GPIO, SRAM,
and flash response handlers also access fixed offsets beyond byte three.

The HID core invokes raw_event callbacks before validating the report
length, so a truncated response can cause an out-of-bounds read.  Require a
complete protocol report before dispatching any response handler.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 67a95c21463d ("HID: mcp2221: add usb to i2c-smbus host bridge")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-mcp2221.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/hid/hid-mcp2221.c b/drivers/hid/hid-mcp2221.c
index d52ce3531ab7..db0b15622c39 100644
--- a/drivers/hid/hid-mcp2221.c
+++ b/drivers/hid/hid-mcp2221.c
@@ -865,7 +865,7 @@ static int mcp2221_raw_event(struct hid_device *hdev,
 	u8 *buf;
 	struct mcp2221 *mcp = hid_get_drvdata(hdev);
 
-	if (size < 4)
+	if (size < sizeof(mcp->txbuf))
 		return 0;
 
 	switch (data[0]) {
-- 
2.34.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-09-24 14:44 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
2026-09-24 14:13 ` [PATCH 01/10] HID: alps: reject short input reports Jiale Yao
2026-09-24 14:13 ` [PATCH 02/10] HID: cougar: reject short special-key reports Jiale Yao
2026-09-24 14:13 ` [PATCH 03/10] HID: cp2112: validate response report lengths Jiale Yao
2026-09-24 14:13 ` [PATCH 04/10] HID: elo: reject short touchscreen reports Jiale Yao
2026-09-24 14:13 ` [PATCH 05/10] HID: logitech-dj: validate unnumbered keyboard reports Jiale Yao
2026-09-24 14:13 ` [PATCH 06/10] HID: mcp2200: validate READ_ALL response length Jiale Yao
2026-09-24 14:13 ` [PATCH 07/10] HID: mcp2221: validate response report length Jiale Yao
2026-09-24 14:13 ` [PATCH 08/10] HID: prodikeys: validate fixed-format MIDI reports Jiale Yao
2026-09-24 14:13 ` [PATCH 09/10] HID: pxrc: reject short input reports Jiale Yao
2026-09-24 14:13 ` [PATCH 10/10] HID: zydacron: validate key report length Jiale Yao
2026-09-24 14:44 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
2026-09-24 14:44 ` [PATCH 07/10] HID: mcp2221: validate response report length Jiale Yao

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®