Re: [syzbot] [hwmon?] KASAN: slab-out-of-bounds Read in aqc_raw_event

Aleksa Savic <[email protected]>
Newsgroups org.kernel.vger.linux-hwmon,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb
Message-ID <[email protected]>
On 8/22/26 6:02 AM, Guenter Roeck wrote:
> Aleksa,
> 
> On 8/21/26 20:06, syzbot wrote:
>> Hello,
>>
>> syzbot found the following issue on:
>>
>> HEAD commit:    e1e6e541c5c9 Merge tag 'thunderbolt-for-v7.3-rc1' of 
>> ssh:/..
>> git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/ 
>> gregkh/usb.git usb-testing
>> console output: https://syzkaller.appspot.com/x/log.txt?x=16086e79580000
>> kernel config:  https://syzkaller.appspot.com/x/.config? 
>> x=8bdeea7ee6735f91
>> dashboard link: https://syzkaller.appspot.com/bug? 
>> extid=9ee5f5dc18673d6b2f37
>> compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils 
>> for Debian) 2.44
>> syz repro:      https://syzkaller.appspot.com/x/repro.syz? 
>> x=14737679580000
>> C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=15a22549580000
>>
>> Downloadable assets:
>> disk image: https://storage.googleapis.com/syzbot-assets/3b0a1f8e6a1f/ 
>> disk-e1e6e541.raw.xz
>> vmlinux: https://storage.googleapis.com/syzbot-assets/f98d855e85e8/ 
>> vmlinux-e1e6e541.xz
>> kernel image: https://storage.googleapis.com/syzbot-assets/ 
>> db2c3a41df6d/bzImage-e1e6e541.xz
>>
>> IMPORTANT: if you fix the issue, please add the following tag to the 
>> commit:
>> Reported-by: [email protected]
>>
>> ==================================================================
>> BUG: KASAN: slab-out-of-bounds in get_unaligned_be16 include/linux/ 
>> unaligned.h:48 [inline]
>> BUG: KASAN: slab-out-of-bounds in aqc_raw_event drivers/hwmon/ 
>> aquacomputer_d5next.c:1345 [inline]
>> BUG: KASAN: slab-out-of-bounds in aqc_raw_event+0x213e/0x25d0 drivers/ 
>> hwmon/aquacomputer_d5next.c:1327
> 
> The problem is that syzkaller sends a bad (short) report.
> aqc_raw_event() needs to validate the report size and bail out
> if it is short. The fix should be straightforard if it is known
> what the minimum report size is. D5NEXT_CTRL_REPORT_SIZE ?
> 
> Thanks,
> Guenter

We do know sizes of control (setting) reports since we send them through 
priv->buffer, but aqc_raw_event() gets sensor reports and their length 
can vary per device. I don't have an exact list for all devices since I 
don't have them all myself. We'll need to verify that what we receive in 
aqc_raw_event() is >= the minimum offset we want to read sensor values from.

Thanks,
Aleksa
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.