Re: [PATCH v3] HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer

Jiri Kosina <[email protected]>
Newsgroups org.kernel.vger.linux-input,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On Thu, 6 Aug 2026, HyeongJun An wrote:

> quickspi_hid_raw_request() receives the caller's buffer length in len, but
> quickspi_get_report() never sees it and copies the whole device-supplied
> response into buf regardless:
> 
>     memcpy(buf, qsdev->report_buf, qsdev->report_len);
> 
> qsdev->report_len comes from the input report the touch controller returns,
> while buf is sized to whatever the caller asked hidraw for through
> HIDIOCGFEATURE or HIDIOCGINPUT.  A response larger than that overflows buf
> with device-controlled content.
> 
> The intel-quicki2c sibling already passes the caller length down to
> quicki2c_get_report() and validates the response against it before the
> copy.  Do the same here.
> 
> Fixes: 4138f21115ae ("HID: intel-thc-hid: intel-quickspi: Complete THC QuickSPI driver")
> Suggested-by: Sashiko AI <[email protected]>
> Cc: [email protected]
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: HyeongJun An <[email protected]>

Applied, thanks.

-- 
Jiri Kosina
SUSE Labs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.