Re: Re: [PATCH v2] HID: intel-ish-hid: clamp HID device count to MAX_HID_DEVICES
srinivas pandruvada <[email protected]> Fri, 31 Jul 2026 07:34:36 -0700
| Newsgroups | org.kernel.vger.linux-input,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 2026-07-31 at 09:46 +0800, [email protected] wrote: > Thanks, +Lixu noted. > > Corrected tag block: > > This patch was drafted with AI assistance. > > Fixes: 0b28cb4bcb17 ("HID: intel-ish-hid: ISH HID client driver") > Cc: [email protected] > Signed-off-by: Shen Yongchao <[email protected]> > Assisted-by: Hermes:kimi-k3 > > Let me know if you want it resent as a proper [PATCH v2]. > Yes with new version. Add Tested by tag also from Lixu. Also some suggestions: - Avoid top posting like this, you can add this part just after your existing tags. - If the patch is long you can trim - I think you use outlook to reply, there are some suggestions of email clients and other suggestions. https://docs.kernel.org/process/email-clients.html Also some other links: https://people.kernel.org/tglx/notes-about-netiquette https://subspace.kernel.org/etiquette.html Thanks, Srinivas > Thanks, > Shen Yongchao > > > > > +Lixu > > > > > > > > > > On Thu, 2026-07-30 at 20:25 +0800, Shen Yongchao wrote: > > > > > > The HOSTIF_DM_ENUM_DEVICES response handler takes the HID device > > > > > > count from the first payload byte of the ISH firmware response > > > > > > (max 255) and stores it in hid_dev_count without any bounds > > > > > > check. This value propagates to num_hid_devices and is used to > > > > > > index five fixed-size arrays in struct ishtp_cl_data > > > > > > (MAX_HID_DEVICES = 32): report_descr[], report_descr_size[], > > > > > > hid_sensor_hubs[], hid_descr[], and hid_descr_size[]. > > > > > > > > > > > > If the firmware reports more than 32 devices, hid_ishtp_cl_init() > > > > > > writes past all five arrays, corrupting subsequent struct fields > > > > > > (including work_struct members with embedded function pointers) > > > > > > and potentially adjacent heap objects. > > > > > > > > > > > > Clamp hid_dev_count to MAX_HID_DEVICES at the single point where > > > > > > it enters the driver (process_recv, ENUM_DEVICES branch), which > > > > > > covers both the probe and the reset paths. > > > > > > > > > > > > This is a data-validation hardening fix: the ISH firmware is > > > > > > within the platform trust boundary (loaded via CSME). > > > > > > > > > > > > This patch was drafted with AI assistance; the vulnerability > > > > > > analysis and source-level verification were done manually. > > > > > > > > > > > > Signed-off-by: Shen Yongchao <[email protected]> > > > > > > Fixes: 0b28cb4bcb17 ("HID: intel-ish-hid: ISH HID client driver") > > > > > > Cc: [email protected] > > > > > > > > > > Missing > > > > > > > > > > Assisted-by: AGENT_NAME:MODEL_VERSION [TOOL1] [TOOL2] > > > > > > > > > > > > > > > Thanks, > > > > > Srinivas > > > > > > > > > > > --- > > > > > > drivers/hid/intel-ish-hid/ishtp-hid-client.c | 2 ++ > > > > > > 1 file changed, 2 insertions(+) > > > > > > > > > > > > diff --git a/drivers/hid/intel-ish-hid/ishtp-hid-client.c > > > > > > b/drivers/hid/intel-ish-hid/ishtp-hid-client.c > > > > > > index 6d64008..XXXXXXX 100644 > > > > > > --- a/drivers/hid/intel-ish-hid/ishtp-hid-client.c > > > > > > +++ b/drivers/hid/intel-ish-hid/ishtp-hid-client.c > > > > > > @@ -123,6 +123,8 @@ static void process_recv(struct ishtp_cl > > > > > > *hid_ishtp_cl, void *recv_buf, > > > > > > break; > > > > > > } > > > > > > client_data->hid_dev_count = (unsigned > > > > > > int)*payload; > > > > > > + if (client_data->hid_dev_count > > > > > > > MAX_HID_DEVICES) > > > > > > + client_data->hid_dev_count = > > > > > > MAX_HID_DEVICES; > > > > > > if (!client_data->hid_devices) > > > > > > client_data->hid_devices = > > > > > > devm_kcalloc( > > > > > > cl_data_to_dev(c > > > lien > > > > > > t_data), >