Linux Input/HID development
 help / color / mirror / Atom feed
* [PATCH RESEND] HID: corsair-void: Fix firmware event packet description
@ 2026-08-18 13:00 Stuart Hayhurst
  2026-08-18 13:29 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Stuart Hayhurst @ 2026-08-18 13:00 UTC (permalink / raw)
  To: linux-input
  Cc: Stuart Hayhurst, linux-kernel, Benjamin Tissoires, Jiri Kosina

The size was incorrectly stated as 4 bytes since the ID was missed out.
Add the ID in and correct the indices for the firmware versions.

Signed-off-by: Stuart Hayhurst <stuart.a.hayhurst@gmail.com>
---
 drivers/hid/hid-corsair-void.c | 15 +++++++++------
 1 file changed, 9 insertions(+), 6 deletions(-)

diff --git a/drivers/hid/hid-corsair-void.c b/drivers/hid/hid-corsair-void.c
index 5e9a5b8f7f16..ce92e3a9c058 100644
--- a/drivers/hid/hid-corsair-void.c
+++ b/drivers/hid/hid-corsair-void.c
@@ -51,20 +51,23 @@
 /* Receiver report information: (ID 102)                                      */
 /* -------------------------------------------------------------------------- */
 /*
- * When queried, the recevier responds with 4 bytes to describe the firmware
- * The first 2 bytes are for the receiver, the second 2 are the headset
+ * When queried, the receiver responds with 5 bytes to describe the firmware
+ * The first byte is the ID, then 2 bytes for the receiver, then 2 for the headset
  * The headset firmware version will be 0 if no headset is connected
  *
- * 0: Recevier firmware major version
+ * 0: Report ID
+ *  102 for the firmware packet
+ *
+ * 1: Receiver firmware major version
  *  Major version of the receiver's firmware
  *
- * 1: Recevier firmware minor version
+ * 2: Receiver firmware minor version
  *  Minor version of the receiver's firmware
  *
- * 2: Headset firmware major version
+ * 3: Headset firmware major version
  *  Major version of the headset's firmware
  *
- * 3: Headset firmware minor version
+ * 4: Headset firmware minor version
  *  Minor version of the headset's firmware
  */
 /* -------------------------------------------------------------------------- */
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH RESEND] HID: corsair-void: Fix firmware event packet description
  2026-08-18 13:00 [PATCH RESEND] HID: corsair-void: Fix firmware event packet description Stuart Hayhurst
@ 2026-08-18 13:29 ` sashiko-bot
  0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-08-18 13:29 UTC (permalink / raw)
  To: Stuart Hayhurst; +Cc: dmitry.torokhov, linux-input

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Medium] Missing report size validation in `corsair_void_raw_event` allows out-of-bounds read of the `data` array, leading to processing of uninitialized or stale data.
--

--- Patch [1]: [PATCH RESEND] HID: corsair-void: Fix firmware event packet description ---
commit 80e19492934a593a71b8da5c14d031065a2f1255
Author: Stuart Hayhurst <stuart.a.hayhurst@gmail.com>

HID: corsair-void: Fix firmware event packet description

This commit updates the firmware event packet description in the corsair-void
driver. It corrects the size to 5 bytes to account for the report ID and
updates the byte indices for the firmware version fields.

> diff --git a/drivers/hid/hid-corsair-void.c b/drivers/hid/hid-corsair-void.c
> index 5e9a5b8f7f167..ce92e3a9c0580 100644
> --- a/drivers/hid/hid-corsair-void.c
> +++ b/drivers/hid/hid-corsair-void.c

[ ... ]

> - * 3: Headset firmware minor version
> + * 4: Headset firmware minor version
>   *  Minor version of the headset's firmware
>   */
>  /* -------------------------------------------------------------------------- */

[Severity: Medium]
This is a pre-existing issue, but since the documentation correctly notes the
receiver responds with 5 bytes, does the driver need to validate this size
before parsing the packet?

In drivers/hid/hid-corsair-void.c:corsair_void_raw_event(), the data array is
accessed up to index 4 without first validating the report size:

	} else if (hid_report->id == CORSAIR_VOID_FIRMWARE_REPORT_ID) {
		drvdata->fw_receiver_major = data[1];
		drvdata->fw_receiver_minor = data[2];
		drvdata->fw_headset_major = data[3];
		drvdata->fw_headset_minor = data[4];
	}

If an untrusted or misbehaving USB device sends a short report where the size
is less than 5, could this lead to an out-of-bounds read and cause the driver
to process uninitialized or stale data from the HID core's input buffer?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260818130053.45064-2-stuart.a.hayhurst@gmail.com?part=1

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-18 13:29 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-18 13:00 [PATCH RESEND] HID: corsair-void: Fix firmware event packet description Stuart Hayhurst
2026-08-18 13:29 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox