From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 47A814D4890; Thu, 17 Sep 2026 15:59:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660758; cv=none; b=pCNdo7COybOPZpvdrf+qmpF4qCr/BL2/mDLAFHZCHTrgsmnl8x8/to3dnD/BwUv6P55enQvxv223xNnRU83tBI1xJW6WaZBbkjac8ZTKfi+iN90BBz1sNwsYogb4L6WuZu4vuSVUxerrJ7Q8S1VKF7VmhUvTw2FIq93KLg9oAFk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660758; c=relaxed/simple; bh=XY34ZP8hVAav2+6pEkcyWfuj2BP7kl7buZV8sXljqq4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=r7cGKxeYAMrgWcesLzeY3vRNh0DdF7Vgf/60Zu1hpS2cUmzHDuZxBmJlQK4w3DseNzUguzFKMnLzBlU4ABx+/GhnrZ5cL8Lm3mdXADRvozmuOgFMCjTWjh9yjsGMLBHxouA1m9lqT2WdF4BDreBskoUTaVSFqqaBHN2Y0t+6GDY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=BPZBfhbc; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="BPZBfhbc" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5F2771F000FF; Thu, 17 Sep 2026 15:59:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789660756; bh=tfk12Zj6wNrWAypMRYOI218JGGfW95rtL55zGtyEYb8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=BPZBfhbc8RRUecXpGR4Fe69qrh8iXRKHubrMdVnLuq76BamFjdtKrFY/Xzi2u4H9s rh0w5iMCnlkYKIHZiVvzv6mpPyDeHz1lACY+oCrsXN19gfd3BSerbSUaRegGpBEVhM dWXW1v6I8muVuksAz6Yf7w/MrHQbZLJxkwKVKOGU= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Sashiko , Arie Miller , Guenter Roeck , Sasha Levin Subject: [PATCH 7.2 697/733] hwmon: (asus_rog_ryujin) Validate HID report lengths Date: Thu, 17 Sep 2026 16:16:45 +0100 Message-ID: <20260917151410.205655107@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Arie Miller [ Upstream commit 8042312e73c50de82634ce63eae7cf219464b481 ] rog_ryujin_raw_event() parses response headers and payload fields without first checking that they are present in the received report. A short report can therefore make the driver consume uninitialized bytes from the HID transport buffer and expose them as sensor values through sysfs. Validate the response header and the fields used by each response type before parsing them. Fixes: ed3e03790c5c ("hwmon: Add driver for ASUS ROG RYUJIN II 360 AIO cooler") Reported-by: Sashiko Closes: https://lore.kernel.org/linux-hwmon/20260812104617.858D01F000E9@smtp.kernel.org/ Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6-sol sparse Signed-off-by: Arie Miller Link: https://patch.msgid.link/20260904022129.97896-2-renari@arimil.com Signed-off-by: Guenter Roeck Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- drivers/hwmon/asus_rog_ryujin.c | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) --- a/drivers/hwmon/asus_rog_ryujin.c +++ b/drivers/hwmon/asus_rog_ryujin.c @@ -411,10 +411,15 @@ static int rog_ryujin_raw_event(struct h { struct rog_ryujin_data *priv = hid_get_drvdata(hdev); - if (data[0] != RYUJIN_CMD_PREFIX) + if (size < 2 || data[0] != RYUJIN_CMD_PREFIX) return 0; if (data[1] == RYUJIN_GET_COOLER_STATUS_CMD_RESPONSE) { + if (size <= priv->info->temp_offset + 1 || + size <= priv->info->pump_speed_offset + 1 || + size <= priv->info->fan_speed_offset + 1) + return 0; + /* Received coolant temp and speeds of pump and internal fan */ priv->temp_input[0] = data[priv->info->temp_offset] * 1000 + data[priv->info->temp_offset + 1] * 100; @@ -426,6 +431,9 @@ static int rog_ryujin_raw_event(struct h if (!completion_done(&priv->cooler_status_received)) complete_all(&priv->cooler_status_received); } else if (data[1] == RYUJIN_GET_CONTROLLER_SPEED_CMD_RESPONSE) { + if (size <= RYUJIN_CONTROLLER_SPEED_3 + 1) + return 0; + /* Received speeds of four fans attached to the controller */ priv->speed_input[2] = get_unaligned_le16(data + RYUJIN_CONTROLLER_SPEED_1); priv->speed_input[3] = get_unaligned_le16(data + RYUJIN_CONTROLLER_SPEED_2); @@ -435,6 +443,9 @@ static int rog_ryujin_raw_event(struct h if (!completion_done(&priv->controller_status_received)) complete_all(&priv->controller_status_received); } else if (data[1] == RYUJIN_GET_COOLER_DUTY_CMD_RESPONSE) { + if (size <= RYUJIN_INTERNAL_FAN_DUTY) + return 0; + /* Received report for pump and internal fan duties (in %) */ if (data[RYUJIN_PUMP_DUTY] == 0 && data[RYUJIN_INTERNAL_FAN_DUTY] == 0) { /* @@ -461,6 +472,9 @@ read_cooler_duty: if (!completion_done(&priv->cooler_duty_received)) complete_all(&priv->cooler_duty_received); } else if (data[1] == RYUJIN_GET_CONTROLLER_DUTY_CMD_RESPONSE) { + if (size <= RYUJIN_CONTROLLER_DUTY) + return 0; + /* Received report for controller duty for fans (in PWM) */ if (data[RYUJIN_CONTROLLER_DUTY] == 0) { /*