Re: [PATCH v2] HID: intel-thc-hid: intel-quickspi: validate report size before copy

Jiri Kosina <[email protected]>
Newsgroups gmane.linux.kernel.stable,gmane.linux.kernel.input,gmane.linux.kernel
Message-ID <[email protected]>
On Fri, 17 Jul 2026, HyeongJun An wrote:

> write_cmd_to_txdma() builds an output report in qsdev->report_buf, a heap
> buffer allocated in quickspi_alloc_report_buf() to the device-descriptor
> derived max_report_len (a few hundred bytes for a touch controller).  It
> copies the caller-supplied report into that buffer:
> 
>     memcpy(write_buf->content, report_buf, report_buf_len);
> 
> The HID core caps a report at HID_MAX_BUFFER_SIZE (16384) by default, and
> quickspi_hid_ll_driver does not set max_buffer_size, so the length reaches
> the driver unbounded.  A hidraw SET_REPORT/SET_FEATURE ioctl carrying a
> report larger than max_report_len therefore overflows report_buf with
> attacker-controlled length and content.
> 
> Record the report_buf allocation size and reject reports that do not fit
> before copying, matching the equivalent guard in the intel-quicki2c
> sibling (quicki2c_init_write_buf()) and the hid-goodix-spi fix.
> 
> write_cmd_to_txdma() writes the output report header ahead of the content
> in the same buffer, so size the allocation to cover the header as well.
> That keeps the added bound from rejecting a maximum-sized report.
> 
> Fixes: 9d8d51735a3a ("HID: intel-thc-hid: intel-quickspi: Add HIDSPI protocol implementation")
> Cc: [email protected]
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: HyeongJun An <[email protected]>
> ---
> v2: Size report_buf to cover the output report header as well, so the added
>     bound cannot reject a valid maximum-sized report (raised by the Sashiko
>     AI review of v1).  No other change.
> 
> v1: https://lore.kernel.org/all/[email protected]/

Applied, thank you.

-- 
Jiri Kosina
SUSE Labs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.