Re: [PATCH] HID: sony: clean up device list on probe failure

Doruk Tan Ozturk <[email protected]>
Newsgroups org.kernel.vger.linux-input
Message-ID <[email protected]>
On Sun, Jul 26, 2026 at 01:04:00PM +0000, [email protected] wrote:
> [Critical] Multiple HID collections in a malicious device cause
> permanent IDA leak and list corruption.

Good catch. A second call to sony_input_configured() would re-allocate
the IDA and double-add to the global list. The fix is a one-line guard
checking sc->device_id >= 0, but it depends on the device_id = -1
initialization from this probe-list cleanup patch. I'll send it once
this one lands.

> [Critical] Missing usb_kill_urb() in sony_remove() leads to a
> Use-After-Free and DMA to freed memory when the URB completes.

This is the ghl_poke_timer/ghl_urb UAF I sent as a separate patch on
July 24:
https://lore.kernel.org/linux-input/[email protected]/

> [High] Unconditional calls to hid_hw_close(hdev) cause
> ll_open_count underflow for devices without battery support.

Confirmed — the err_close path calls hid_hw_close() even when the
device lacks SONY_BATTERY_SUPPORT and hid_hw_open() was never called.
A guard on the quirk would fix it. Separate issue from this patch.

-Doruk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.