Re: [syzbot] [hwmon?] KASAN: slab-out-of-bounds Read in aqc_raw_event

Guenter Roeck <[email protected]>
Newsgroups org.kernel.vger.linux-hwmon,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb
Message-ID <[email protected]>
On 8/22/26 01:07, Aleksa Savic wrote:
> On 8/22/26 6:02 AM, Guenter Roeck wrote:
>> Aleksa,
>>
>> On 8/21/26 20:06, syzbot wrote:
>>> Hello,
>>>
>>> syzbot found the following issue on:
>>>
>>> HEAD commit:    e1e6e541c5c9 Merge tag 'thunderbolt-for-v7.3-rc1' of ssh:/..
>>> git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/ gregkh/usb.git usb-testing
>>> console output: https://syzkaller.appspot.com/x/log.txt?x=16086e79580000
>>> kernel config:  https://syzkaller.appspot.com/x/.config? x=8bdeea7ee6735f91
>>> dashboard link: https://syzkaller.appspot.com/bug? extid=9ee5f5dc18673d6b2f37
>>> compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
>>> syz repro:      https://syzkaller.appspot.com/x/repro.syz? x=14737679580000
>>> C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=15a22549580000
>>>
>>> Downloadable assets:
>>> disk image: https://storage.googleapis.com/syzbot-assets/3b0a1f8e6a1f/ disk-e1e6e541.raw.xz
>>> vmlinux: https://storage.googleapis.com/syzbot-assets/f98d855e85e8/ vmlinux-e1e6e541.xz
>>> kernel image: https://storage.googleapis.com/syzbot-assets/ db2c3a41df6d/bzImage-e1e6e541.xz
>>>
>>> IMPORTANT: if you fix the issue, please add the following tag to the commit:
>>> Reported-by: [email protected]
>>>
>>> ==================================================================
>>> BUG: KASAN: slab-out-of-bounds in get_unaligned_be16 include/linux/ unaligned.h:48 [inline]
>>> BUG: KASAN: slab-out-of-bounds in aqc_raw_event drivers/hwmon/ aquacomputer_d5next.c:1345 [inline]
>>> BUG: KASAN: slab-out-of-bounds in aqc_raw_event+0x213e/0x25d0 drivers/ hwmon/aquacomputer_d5next.c:1327
>>
>> The problem is that syzkaller sends a bad (short) report.
>> aqc_raw_event() needs to validate the report size and bail out
>> if it is short. The fix should be straightforard if it is known
>> what the minimum report size is. D5NEXT_CTRL_REPORT_SIZE ?
>>
>> Thanks,
>> Guenter
> 
> We do know sizes of control (setting) reports since we send them through priv->buffer, but aqc_raw_event() gets sensor reports and their length can vary per device. I don't have an exact list for all devices since I don't have them all myself. We'll need to verify that what we receive in aqc_raw_event() is >= the minimum offset we want to read sensor values from.

Agreed. We'll need something like min_raw_report_size per device.
It doesn't have to be accurate, just large enough to cover all values
that are extracted from the report. I think for D5 that would be
110 (D5NEXT_PUMP_OFFSET + 3), but I may have miscalculated it.

Thanks,
Guenter
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.