[PATCH] HID: core: check field offset before dumping input
Deepanshu Kartikey <[email protected]> Sun, 9 Aug 2026 09:36:29 +0530
| Newsgroups | org.kernel.vger.linux-input,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
hid_set_field() passes field->usage + offset to hid_dump_input() before validating offset against field->report_count. field->usage is allocated with exactly report_count entries, so a larger offset is read out of bounds before the existing check rejects it: BUG: KASAN: slab-out-of-bounds in hid_dump_input+0xcb/0xd0 Read of size 4 at addr ffff88802ab28fc0 by task kworker/1:2/48 Move the bounds check above the hid_dump_input() call so the function returns before the dereference. Reported-by: [email protected] Closes: https://syzkaller.appspot.com/bug?extid=a942efa43c928a1e3daa Tested-by: [email protected] Signed-off-by: Deepanshu Kartikey <[email protected]> --- drivers/hid/hid-core.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c index cf123347a2af..7ea1fb62b9d4 100644 --- a/drivers/hid/hid-core.c +++ b/drivers/hid/hid-core.c @@ -1933,13 +1933,14 @@ int hid_set_field(struct hid_field *field, unsigned offset, __s32 value) size = field->report_size; - hid_dump_input(field->report->device, field->usage + offset, value); - if (offset >= field->report_count) { hid_err(field->report->device, "offset (%d) exceeds report_count (%d)\n", offset, field->report_count); return -1; } + + hid_dump_input(field->report->device, field->usage + offset, value); + if (field->logical_minimum < 0) { if (value != snto32(s32ton(value, size), size)) { hid_err(field->report->device, "value %d is out of range\n", value); -- 2.43.0