Re: [PATCH v2] HID: intel-thc-hid: intel-quickspi: validate report size before copy

Jiri Kosina <[email protected]> Mon, 3 Aug 2026 19:45:12 +0200 (CEST)
Newsgroups org.kernel.vger.linux-input,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On Fri, 17 Jul 2026, HyeongJun An wrote:

> write_cmd_to_txdma() builds an output report in qsdev->report_buf, a heap
> buffer allocated in quickspi_alloc_report_buf() to the device-descriptor
> derived max_report_len (a few hundred bytes for a touch controller).  It
> copies the caller-supplied report into that buffer:
> 
>     memcpy(write_buf->content, report_buf, report_buf_len);
> 
> The HID core caps a report at HID_MAX_BUFFER_SIZE (16384) by default, and
> quickspi_hid_ll_driver does not set max_buffer_size, so the length reaches
> the driver unbounded.  A hidraw SET_REPORT/SET_FEATURE ioctl carrying a
> report larger than max_report_len therefore overflows report_buf with
> attacker-controlled length and content.
> 
> Record the report_buf allocation size and reject reports that do not fit
> before copying, matching the equivalent guard in the intel-quicki2c
> sibling (quicki2c_init_write_buf()) and the hid-goodix-spi fix.
> 
> write_cmd_to_txdma() writes the output report header ahead of the content
> in the same buffer, so size the allocation to cover the header as well.
> That keeps the added bound from rejecting a maximum-sized report.
> 
> Fixes: 9d8d51735a3a ("HID: intel-thc-hid: intel-quickspi: Add HIDSPI protocol implementation")
> Cc: [email protected]
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: HyeongJun An <[email protected]>
> ---
> v2: Size report_buf to cover the output report header as well, so the added
>     bound cannot reject a valid maximum-sized report (raised by the Sashiko
>     AI review of v1).  No other change.
> 
> v1: https://lore.kernel.org/all/[email protected]/

Applied, thank you.

-- 
Jiri Kosina
SUSE Labs