Re: [PATCH] HID: core: check field offset before dumping input
Deepanshu Kartikey <[email protected]>
| Newsgroups | org.kernel.vger.linux-input,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CADhLXY4_M62zOXOCyk8BcBU924+7_TxZ_GkbE=V5ME3ZbDsVag@mail.gmail.com> |
On Sun, Aug 9, 2026 at 9:36 AM Deepanshu Kartikey <[email protected]> wrote: > > hid_set_field() passes field->usage + offset to hid_dump_input() before > validating offset against field->report_count. field->usage is allocated > with exactly report_count entries, so a larger offset is read out of > bounds before the existing check rejects it: > > BUG: KASAN: slab-out-of-bounds in hid_dump_input+0xcb/0xd0 > Read of size 4 at addr ffff88802ab28fc0 by task kworker/1:2/48 > > Move the bounds check above the hid_dump_input() call so the function > returns before the dereference. > > Reported-by: [email protected] > Closes: https://syzkaller.appspot.com/bug?extid=a942efa43c928a1e3daa > Tested-by: [email protected] > Signed-off-by: Deepanshu Kartikey <[email protected]> > --- > drivers/hid/hid-core.c | 5 +++-- > 1 file changed, 3 insertions(+), 2 deletions(-) > > diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c > index cf123347a2af..7ea1fb62b9d4 100644 > --- a/drivers/hid/hid-core.c > +++ b/drivers/hid/hid-core.c > @@ -1933,13 +1933,14 @@ int hid_set_field(struct hid_field *field, unsigned offset, __s32 value) > > size = field->report_size; > > - hid_dump_input(field->report->device, field->usage + offset, value); > - > if (offset >= field->report_count) { > hid_err(field->report->device, "offset (%d) exceeds report_count (%d)\n", > offset, field->report_count); > return -1; > } > + > + hid_dump_input(field->report->device, field->usage + offset, value); > + > if (field->logical_minimum < 0) { > if (value != snto32(s32ton(value, size), size)) { > hid_err(field->report->device, "value %d is out of range\n", value); > -- > 2.43.0 > Gentle Reminder. Please let me know the status of this patch Thanks Deepanshu