Re: [PATCH] hwmon: valid the data size before reading the sensor data

Edward Adam Davis <[email protected]>
Newsgroups org.kernel.vger.linux-hwmon,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb
Message-ID <[email protected]>
On Fri, 21 Aug 2026 23:41:26 -0700, Guenter Roeck wrote:
> Subject is supposed to be "hwmon: (driver) Description".
Oh, got it.
> 
> On 8/21/26 22:34, Edward Adam Davis wrote:
> > The user-forged sensor data is only 65 bytes long; however, aqc_raw_event()
> > fails to handle cases where the sensor data length is smaller than the buffer
> > size when reading the data, resulting in [1] during the read process.
> >
> 
> The device simulated by syzbot is D5 next, and its control buffer size is
> 0x329 or 809. I _asked_ earlier if that is the value to check against,
> but did not claim that this is actually the case.
> 
> We know that the report must be much longer than 65 bytes. D5NEXT_PUMP_OFFSET
> is 0x6c = 108, and the field is two bytes long, meaning the report size
> must be at least 110 bytes long. What we do not know is its actual length.
> 
> > Add a check for the data size, if it less than the buffer size, the sensor
> > data read is aborted.
> >
> 
> Apparently Sashiko is aware that this is wrong - not only is the report size
> smaller than 809 bytes, but apparently buffer_size is not even set for all
> supported devices.
Yes, I also realized that relying solely on the buffer size for the check
might be too simplistic or crude, so I adjusted the data length verification
method and submitted a second version of the patch.

BR,
Edward
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.