From: Lee Jones <lee.jones@linaro.org>
To: linux-kernel@vger.kernel.org, Jiri Kosina <jikos@kernel.org>,
Benjamin Tissoires <benjamin.tissoires@redhat.com>,
linux-input@vger.kernel.org
Subject: Re: [PATCH 1/1] HID: steam: Prevent NULL pointer dereference in steam_{recv,send}_report
Date: Tue, 19 Jul 2022 16:43:45 +0100 [thread overview]
Message-ID: <YtbRMUSa8KyOtd1x@google.com> (raw)
In-Reply-To: <20220708074009.621113-1-lee.jones@linaro.org>
On Fri, 08 Jul 2022, Lee Jones wrote:
> It is possible for a malicious device to forgo submitting a Feature
> Report. The HID Steam driver presently makes no prevision for this
> and de-references the 'struct hid_report' pointer obtained from the
> HID devices without first checking its validity. Let's change that.
>
> Cc: Jiri Kosina <jikos@kernel.org>
> Cc: Benjamin Tissoires <benjamin.tissoires@redhat.com>
> Cc: linux-input@vger.kernel.org
> Fixes: c164d6abf3841 ("HID: add driver for Valve Steam Controller")
> Signed-off-by: Lee Jones <lee.jones@linaro.org>
> ---
> drivers/hid/hid-steam.c | 10 ++++++++++
> 1 file changed, 10 insertions(+)
Did anyone get a chance to look at this?
Would you like me to submit a [RESEND]?
> diff --git a/drivers/hid/hid-steam.c b/drivers/hid/hid-steam.c
> index a3b151b29bd71..fc616db4231bb 100644
> --- a/drivers/hid/hid-steam.c
> +++ b/drivers/hid/hid-steam.c
> @@ -134,6 +134,11 @@ static int steam_recv_report(struct steam_device *steam,
> int ret;
>
> r = steam->hdev->report_enum[HID_FEATURE_REPORT].report_id_hash[0];
> + if (!r) {
> + hid_err(steam->hdev, "No HID_FEATURE_REPORT submitted - nothing to read\n");
> + return -EINVAL;
> + }
> +
> if (hid_report_len(r) < 64)
> return -EINVAL;
>
> @@ -165,6 +170,11 @@ static int steam_send_report(struct steam_device *steam,
> int ret;
>
> r = steam->hdev->report_enum[HID_FEATURE_REPORT].report_id_hash[0];
> + if (!r) {
> + hid_err(steam->hdev, "No HID_FEATURE_REPORT submitted - nothing to read\n");
> + return -EINVAL;
> + }
> +
> if (hid_report_len(r) < 64)
> return -EINVAL;
>
--
Lee Jones [李琼斯]
Principal Technical Lead - Developer Services
Linaro.org │ Open source software for Arm SoCs
Follow Linaro: Facebook | Twitter | Blog
next prev parent reply other threads:[~2022-07-19 15:43 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-07-08 7:40 [PATCH 1/1] HID: steam: Prevent NULL pointer dereference in steam_{recv,send}_report Lee Jones
2022-07-19 15:43 ` Lee Jones [this message]
2022-08-25 8:22 ` Jiri Kosina
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=YtbRMUSa8KyOtd1x@google.com \
--to=lee.jones@linaro.org \
--cc=benjamin.tissoires@redhat.com \
--cc=jikos@kernel.org \
--cc=linux-input@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.