mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jiale Yao <yaojiale02@163.com>
To: Rishi Gupta <gupt21@gmail.com>, Jiri Kosina <jikos@kernel.org>,
	Benjamin Tissoires <bentiss@kernel.org>,
	linux-i2c@vger.kernel.org, linux-input@vger.kernel.org,
	linux-kernel@vger.kernel.org
Cc: Jiale Yao <yaojiale02@163.com>, stable@vger.kernel.org
Subject: [PATCH 07/10] HID: mcp2221: validate response report length
Date: Thu, 24 Sep 2026 22:44:10 +0800	[thread overview]
Message-ID: <20260924144414.1192037-8-yaojiale02@163.com> (raw)
In-Reply-To: <20260924144414.1192037-1-yaojiale02@163.com>

MCP2221 responses are 64-byte reports, but mcp2221_raw_event() currently
accepts any report of at least four bytes.  Several response handlers read
far beyond that minimum.  In particular, the I2C status response reads
offset 20 and copies ADC samples starting at offset 50.  Other GPIO, SRAM,
and flash response handlers also access fixed offsets beyond byte three.

The HID core invokes raw_event callbacks before validating the report
length, so a truncated response can cause an out-of-bounds read.  Require a
complete protocol report before dispatching any response handler.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 67a95c21463d ("HID: mcp2221: add usb to i2c-smbus host bridge")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/hid/hid-mcp2221.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/hid/hid-mcp2221.c b/drivers/hid/hid-mcp2221.c
index d52ce3531ab7..db0b15622c39 100644
--- a/drivers/hid/hid-mcp2221.c
+++ b/drivers/hid/hid-mcp2221.c
@@ -865,7 +865,7 @@ static int mcp2221_raw_event(struct hid_device *hdev,
 	u8 *buf;
 	struct mcp2221 *mcp = hid_get_drvdata(hdev);
 
-	if (size < 4)
+	if (size < sizeof(mcp->txbuf))
 		return 0;
 
 	switch (data[0]) {
-- 
2.34.1


  parent reply	other threads:[~2026-09-24 14:44 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 14:44 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
2026-09-24 14:44 ` [PATCH 01/10] HID: alps: reject short input reports Jiale Yao
2026-09-24 14:44 ` [PATCH 02/10] HID: cougar: reject short special-key reports Jiale Yao
2026-09-24 14:44 ` [PATCH 03/10] HID: cp2112: validate response report lengths Jiale Yao
2026-09-24 14:44 ` [PATCH 04/10] HID: elo: reject short touchscreen reports Jiale Yao
2026-09-24 14:44 ` [PATCH 05/10] HID: logitech-dj: validate unnumbered keyboard reports Jiale Yao
2026-09-24 14:44 ` [PATCH 06/10] HID: mcp2200: validate READ_ALL response length Jiale Yao
2026-09-24 14:44 ` Jiale Yao [this message]
2026-09-24 14:44 ` [PATCH 08/10] HID: prodikeys: validate fixed-format MIDI reports Jiale Yao
2026-09-24 14:44 ` [PATCH 09/10] HID: pxrc: reject short input reports Jiale Yao
2026-09-24 14:44 ` [PATCH 10/10] HID: zydacron: validate key report length Jiale Yao
  -- strict thread matches above, loose matches on Subject: below --
2026-09-24 14:13 [PATCH 00/10] HID: validate short reports in raw_event callbacks Jiale Yao
2026-09-24 14:13 ` [PATCH 07/10] HID: mcp2221: validate response report length Jiale Yao

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924144414.1192037-8-yaojiale02@163.com \
    --to=yaojiale02@163.com \
    --cc=bentiss@kernel.org \
    --cc=gupt21@gmail.com \
    --cc=jikos@kernel.org \
    --cc=linux-i2c@vger.kernel.org \
    --cc=linux-input@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®