diff options
| author | Lee Jones <lee@kernel.org> | 2026-06-16 11:26:56 +0000 |
|---|---|---|
| committer | Jiri Kosina <jkosina@suse.com> | 2026-06-29 11:10:23 +0200 |
| commit | af1a9b65ebe8a948eda805c14b78d4d0767cb1b5 (patch) | |
| tree | ec2df2bfcf632e15962323dd1d35d75ed895060a /rust/zerocopy/git@git.tavy.me:linux-stable.git | |
| parent | 0021eb09041f021c079be1022934a280f7f176c0 (diff) | |
HID: core: Fix OOB read in hid_get_report for numbered reports
When a caller passes a size of 0 to hid_report_raw_event() for a
numbered report, the function originally called hid_get_report() before
performing any size validation.
Inside hid_get_report(), if the report is numbered (report_enum->numbered
is true), it unconditionally dereferences data[0] to extract the report ID.
With a size of 0, this results in an out-of-bounds read or kernel panic.
Fix this by moving the numbered report size validation check before the
call to hid_get_report(), ensuring that size is at least 1 before
dereferencing the data pointer.
Fixes: 2c85c61d1332 ("HID: pass the buffer size to hid_report_raw_event")
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Diffstat (limited to 'rust/zerocopy/git@git.tavy.me:linux-stable.git')
0 files changed, 0 insertions, 0 deletions
