Re: Re: [PATCH v2] HID: intel-ish-hid: clamp HID device count to MAX_HID_DEVICES

"[email protected]" <[email protected]> Fri, 31 Jul 2026 09:46:43 +0800
Newsgroups org.kernel.vger.linux-input,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Thanks, +Lixu noted.

Corrected tag block:

This patch was drafted with AI assistance.

Fixes: 0b28cb4bcb17 ("HID: intel-ish-hid: ISH HID client driver")
Cc: [email protected]
Signed-off-by: Shen Yongchao <[email protected]>
Assisted-by: Hermes:kimi-k3

Let me know if you want it resent as a proper [PATCH v2].

Thanks,
Shen Yongchao



>+Lixu



>



>On Thu, 2026-07-30 at 20:25 +0800, Shen Yongchao wrote:



>> The HOSTIF_DM_ENUM_DEVICES response handler takes the HID device



>> count from the first payload byte of the ISH firmware response



>> (max 255) and stores it in hid_dev_count without any bounds



>> check.  This value propagates to num_hid_devices and is used to



>> index five fixed-size arrays in struct ishtp_cl_data



>> (MAX_HID_DEVICES = 32): report_descr[], report_descr_size[],



>> hid_sensor_hubs[], hid_descr[], and hid_descr_size[].



>> 



>> If the firmware reports more than 32 devices, hid_ishtp_cl_init()



>> writes past all five arrays, corrupting subsequent struct fields



>> (including work_struct members with embedded function pointers)



>> and potentially adjacent heap objects.



>> 



>> Clamp hid_dev_count to MAX_HID_DEVICES at the single point where



>> it enters the driver (process_recv, ENUM_DEVICES branch), which



>> covers both the probe and the reset paths.



>> 



>> This is a data-validation hardening fix: the ISH firmware is



>> within the platform trust boundary (loaded via CSME).



>> 



>> This patch was drafted with AI assistance; the vulnerability



>> analysis and source-level verification were done manually.



>> 



>> Signed-off-by: Shen Yongchao <[email protected]>



>> Fixes: 0b28cb4bcb17 ("HID: intel-ish-hid: ISH HID client driver")



>> Cc: [email protected]



>



>Missing



>



>Assisted-by: AGENT_NAME:MODEL_VERSION [TOOL1] [TOOL2]



>



>



>Thanks,



>Srinivas



>



>> ---



>>  drivers/hid/intel-ish-hid/ishtp-hid-client.c | 2 ++



>>  1 file changed, 2 insertions(+)



>> 



>> diff --git a/drivers/hid/intel-ish-hid/ishtp-hid-client.c



>> b/drivers/hid/intel-ish-hid/ishtp-hid-client.c



>> index 6d64008..XXXXXXX 100644



>> --- a/drivers/hid/intel-ish-hid/ishtp-hid-client.c



>> +++ b/drivers/hid/intel-ish-hid/ishtp-hid-client.c



>> @@ -123,6 +123,8 @@ static void process_recv(struct ishtp_cl



>> *hid_ishtp_cl, void *recv_buf,



>>  				break;



>>  			}



>>  			client_data->hid_dev_count = (unsigned



>> int)*payload;



>> +			if (client_data->hid_dev_count >



>> MAX_HID_DEVICES)



>> +				client_data->hid_dev_count =



>> MAX_HID_DEVICES;



>>  			if (!client_data->hid_devices)



>>  				client_data->hid_devices =



>> devm_kcalloc(



>>  						cl_data_to_dev(clien



>> t_data),