Re: [PATCH] usb: misc: usbio: fix bulk receive overread

Griffin Kroah-Hartman <[email protected]> Thu, 6 Aug 2026 16:07:48 +0200
Newsgroups org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 8/6/26 4:03 PM, Alan Stern wrote:
> On Thu, Aug 06, 2026 at 03:43:11PM +0200, Griffin Kroah-Hartman wrote:
>> Add a check for bpkt_len being more than what was actually sent from the
>> device in usbio_bulk_msg().
>>
>> A malicious device could use this vulnerability to claim that more data
>> was sent, when in reality it was not, leading to an OOB read later on
>> with the memcpy at the end of the function.
>>
>> Cc: [email protected]
>> Assisted-by: gkh_clanker_t1000
>> Signed-off-by: Griffin Kroah-Hartman <[email protected]>
>> ---
>>   drivers/usb/misc/usbio.c | 3 +++
>>   1 file changed, 3 insertions(+)
>>
>> diff --git a/drivers/usb/misc/usbio.c b/drivers/usb/misc/usbio.c
>> index 3c2474dca810..794322ff09fd 100644
>> --- a/drivers/usb/misc/usbio.c
>> +++ b/drivers/usb/misc/usbio.c
>> @@ -341,6 +341,9 @@ int usbio_bulk_msg(struct auxiliary_device *adev, u8 type, u8 cmd, bool last,
>>   	if (bpkt->header.flags & USBIO_PKTFLAG_ERR)
>>   		return -EREMOTEIO;
>>   
>> +	if (bpkt_len > act - sizeof(*bpkt))
>> +		return -EPROTO;
>> +
> Isn't this just a repeat of the code sitting 4 lines below?
oops, sorry I was working off of Linus's Tree, not linux-next :(

Griffin