From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D83F0305E3B; Tue, 21 Jul 2026 22:01:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784671274; cv=none; b=J5wKg5GqnGoVb6EqP5J0XBQwzFB5Pmh4+enL92thyUaMcrtDf1qkWunvRVFvq1Q/q88PQng6Oxa3Rr3Dca2xSB6A+8K13cxcl/RkTf8vT0mAIjQspFo2EzPOJs1da8mYWHXMC8o3tMoRDNUZ1c/9eF/40nKewgpL6bK5UZquaxQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784671274; c=relaxed/simple; bh=aWUWxzID86jCy43m1d8k8kXcH94C07li4UuzpAaMKFo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=IpAI7B5glpm7WvA3NlGfgXBBM2xuj1ZaM+MQ5x1x9fr36Fzfle1dyBMxwpCKCWSvSPvx4o0leAPK3s2yRkYjDuyjYen9E07pc/h6opuDlbxUyAUrM/il+5NuX8npPLMYnVVldhR8aUbEHdRFDi7JQdvtjr2aRTLgXDMmXmdi2g8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=y26UglKS; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="y26UglKS" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 41ED61F000E9; Tue, 21 Jul 2026 22:01:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1784671273; bh=s9YaRj+297zCaym31EyN9opaXYIYp06ma9Ikm0Cxn1I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=y26UglKSooZPxOz0NF3zbfexj6owBNUEwXt+aBlPFAwL8z8gvBQ+JpkXHMeepjyvL iaTEkmeOzvYvtFFt8qUMttwJCNwco9tvCOh3x/6d6SN7l21IBT5RqNhBZleHm9PhmJ Biu37vSdqg6mMMd7qpIDItj3MSU81Tm7Xirqcg1A= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Bryam Vargas , Hans de Goede , Dmitry Torokhov Subject: [PATCH 5.15 185/843] Input: goodix - clamp the device-reported contact count Date: Tue, 21 Jul 2026 17:17:00 +0200 Message-ID: <20260721152410.176735474@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260721152405.946368001@linuxfoundation.org> References: <20260721152405.946368001@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.15-stable review patch. If anyone has any objections, please let me know. ------------------ From: Bryam Vargas commit 5ed62a96e06be4e94b8296b7932afee550a70e04 upstream. goodix_ts_read_input_report() copies the number of touch points reported by the device into an on-stack buffer u8 point_data[2 + GOODIX_MAX_CONTACT_SIZE * GOODIX_MAX_CONTACTS]; which is sized for at most GOODIX_MAX_CONTACTS (10) contacts. The only runtime check bounds the per-interrupt count against ts->max_touch_num, but that value is taken verbatim from a 4-bit field of the device configuration block and is never clamped: ts->max_touch_num = ts->config[MAX_CONTACTS_LOC] & 0x0f; The nibble can be 0..15, so a malfunctioning, malicious or counterfeit controller (or an attacker tampering with the I2C bus) can advertise up to 15 contacts. goodix_ts_read_input_report() then accepts a touch_num of up to 15 and the second goodix_i2c_read() writes ts->contact_size * (touch_num - 1) bytes past the one-contact header into point_data - up to 30 bytes (45 with the 9-byte report format) beyond the 92-byte buffer: a stack out-of-bounds write. Clamp max_touch_num to GOODIX_MAX_CONTACTS, the number of contacts point_data[] is sized for, when reading it from the configuration. Fixes: a7ac7c95d468 ("Input: goodix - use max touch number from device config") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas Reviewed-by: Hans de Goede Link: https://patch.msgid.link/20260612-b4-disp-6844625d-v1-1-df0aed080c9d@proton.me Signed-off-by: Dmitry Torokhov Signed-off-by: Greg Kroah-Hartman --- drivers/input/touchscreen/goodix.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) --- a/drivers/input/touchscreen/goodix.c +++ b/drivers/input/touchscreen/goodix.c @@ -935,7 +935,8 @@ static void goodix_read_config(struct go } ts->int_trigger_type = ts->config[TRIGGER_LOC] & 0x03; - ts->max_touch_num = ts->config[MAX_CONTACTS_LOC] & 0x0f; + ts->max_touch_num = min(ts->config[MAX_CONTACTS_LOC] & 0x0f, + GOODIX_MAX_CONTACTS); x_max = get_unaligned_le16(&ts->config[RESOLUTION_LOC]); y_max = get_unaligned_le16(&ts->config[RESOLUTION_LOC + 2]);