Re: [PATCH v3] HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
Jiri Kosina <[email protected]>
| Newsgroups | org.kernel.vger.linux-input,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 6 Aug 2026, HyeongJun An wrote:
> quickspi_hid_raw_request() receives the caller's buffer length in len, but
> quickspi_get_report() never sees it and copies the whole device-supplied
> response into buf regardless:
>
> memcpy(buf, qsdev->report_buf, qsdev->report_len);
>
> qsdev->report_len comes from the input report the touch controller returns,
> while buf is sized to whatever the caller asked hidraw for through
> HIDIOCGFEATURE or HIDIOCGINPUT. A response larger than that overflows buf
> with device-controlled content.
>
> The intel-quicki2c sibling already passes the caller length down to
> quicki2c_get_report() and validates the response against it before the
> copy. Do the same here.
>
> Fixes: 4138f21115ae ("HID: intel-thc-hid: intel-quickspi: Complete THC QuickSPI driver")
> Suggested-by: Sashiko AI <[email protected]>
> Cc: [email protected]
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: HyeongJun An <[email protected]>
Applied, thanks.
--
Jiri Kosina
SUSE Labs