Forwarded: [PATCH] HID: core: check field offset before dumping input

syzbot <[email protected]>
Newsgroups gmane.linux.kernel
Message-ID <[email protected]>
For archival purposes, forwarding an incoming command email to
[email protected], [email protected].

***

Subject: [PATCH] HID: core: check field offset before dumping input
Author: [email protected]

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master


hid_set_field() passes field->usage + offset to hid_dump_input() before
validating offset against field->report_count. field->usage is allocated
with exactly report_count entries, so a larger offset is read out of
bounds before the existing check rejects it:

  BUG: KASAN: slab-out-of-bounds in hid_dump_input+0xcb/0xd0
  Read of size 4 at addr ffff88802ab28fc0 by task kworker/1:2/48

Move the bounds check above the hid_dump_input() call so the function
returns before the dereference.

Reported-by: [email protected]
Closes: https://syzkaller.appspot.com/bug?extid=a942efa43c928a1e3daa
Signed-off-by: Deepanshu Kartikey <[email protected]>
---
 drivers/hid/hid-core.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
index cf123347a2af..7ea1fb62b9d4 100644
--- a/drivers/hid/hid-core.c
+++ b/drivers/hid/hid-core.c
@@ -1933,13 +1933,14 @@ int hid_set_field(struct hid_field *field, unsigned offset, __s32 value)
 
 	size = field->report_size;
 
-	hid_dump_input(field->report->device, field->usage + offset, value);
-
 	if (offset >= field->report_count) {
 		hid_err(field->report->device, "offset (%d) exceeds report_count (%d)\n",
 				offset, field->report_count);
 		return -1;
 	}
+
+	hid_dump_input(field->report->device, field->usage + offset, value);
+
 	if (field->logical_minimum < 0) {
 		if (value != snto32(s32ton(value, size), size)) {
 			hid_err(field->report->device, "value %d is out of range\n", value);
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.