Re: [PATCH] HID: core: check field offset before dumping input

Deepanshu Kartikey <[email protected]>
Newsgroups org.kernel.vger.linux-input,org.kernel.vger.linux-kernel
Message-ID <CADhLXY4_M62zOXOCyk8BcBU924+7_TxZ_GkbE=V5ME3ZbDsVag@mail.gmail.com>
On Sun, Aug 9, 2026 at 9:36 AM Deepanshu Kartikey <[email protected]> wrote:
>
> hid_set_field() passes field->usage + offset to hid_dump_input() before
> validating offset against field->report_count. field->usage is allocated
> with exactly report_count entries, so a larger offset is read out of
> bounds before the existing check rejects it:
>
>   BUG: KASAN: slab-out-of-bounds in hid_dump_input+0xcb/0xd0
>   Read of size 4 at addr ffff88802ab28fc0 by task kworker/1:2/48
>
> Move the bounds check above the hid_dump_input() call so the function
> returns before the dereference.
>
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=a942efa43c928a1e3daa
> Tested-by: [email protected]
> Signed-off-by: Deepanshu Kartikey <[email protected]>
> ---
>  drivers/hid/hid-core.c | 5 +++--
>  1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
> index cf123347a2af..7ea1fb62b9d4 100644
> --- a/drivers/hid/hid-core.c
> +++ b/drivers/hid/hid-core.c
> @@ -1933,13 +1933,14 @@ int hid_set_field(struct hid_field *field, unsigned offset, __s32 value)
>
>         size = field->report_size;
>
> -       hid_dump_input(field->report->device, field->usage + offset, value);
> -
>         if (offset >= field->report_count) {
>                 hid_err(field->report->device, "offset (%d) exceeds report_count (%d)\n",
>                                 offset, field->report_count);
>                 return -1;
>         }
> +
> +       hid_dump_input(field->report->device, field->usage + offset, value);
> +
>         if (field->logical_minimum < 0) {
>                 if (value != snto32(s32ton(value, size), size)) {
>                         hid_err(field->report->device, "value %d is out of range\n", value);
> --
> 2.43.0
>

Gentle Reminder. Please let me know the status of this patch

Thanks

Deepanshu
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.