summaryrefslogtreecommitdiff
path: root/rust/zerocopy/git@git.tavy.me:linux-stable.git
diff options
context:
space:
mode:
authorLee Jones <lee@kernel.org>2026-06-16 11:26:56 +0000
committerJiri Kosina <jkosina@suse.com>2026-06-29 11:10:23 +0200
commitaf1a9b65ebe8a948eda805c14b78d4d0767cb1b5 (patch)
treeec2df2bfcf632e15962323dd1d35d75ed895060a /rust/zerocopy/git@git.tavy.me:linux-stable.git
parent0021eb09041f021c079be1022934a280f7f176c0 (diff)
HID: core: Fix OOB read in hid_get_report for numbered reports
When a caller passes a size of 0 to hid_report_raw_event() for a numbered report, the function originally called hid_get_report() before performing any size validation. Inside hid_get_report(), if the report is numbered (report_enum->numbered is true), it unconditionally dereferences data[0] to extract the report ID. With a size of 0, this results in an out-of-bounds read or kernel panic. Fix this by moving the numbered report size validation check before the call to hid_get_report(), ensuring that size is at least 1 before dereferencing the data pointer. Fixes: 2c85c61d1332 ("HID: pass the buffer size to hid_report_raw_event") Signed-off-by: Lee Jones <lee@kernel.org> Signed-off-by: Jiri Kosina <jkosina@suse.com>
Diffstat (limited to 'rust/zerocopy/git@git.tavy.me:linux-stable.git')
0 files changed, 0 insertions, 0 deletions