From: Yibo Tan <lhfff@tju.edu.cn>
To: Jiri Kosina <jikos@kernel.org>,
Jonathan Cameron <jic23@kernel.org>,
Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>,
Benjamin Tissoires <bentiss@kernel.org>
Cc: Zhang Lixu <lixu.zhang@intel.com>,
Andy Shevchenko <andriy.shevchenko@intel.com>,
linux-input@vger.kernel.org, linux-iio@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v1] HID: sensor-hub: synchronize multi-value read cancellation
Date: Thu, 10 Sep 2026 19:23:38 +0800 [thread overview]
Message-ID: <20260910112338.4171983-1-lhfff@tju.edu.cn> (raw)
sensor_hub_input_attr_read_values() publishes a caller-owned buffer to the
raw-event path. If its interruptible wait times out or is interrupted, it
clears pending.status without taking data->lock and returns.
sensor_hub_raw_event() may already have observed pending.status while
holding that lock. The caller can then release its buffer before raw-event
finishes copying into it.
Take data->lock when cancelling the request. The raw-event path now either
sees the request retired or finishes the copy before cancellation can
return.
On an uninstrumented PREEMPT_RT kernel, a valid 16-byte quaternion report
overwrote a live futex waiter's plist node with the report's 0x41 payload.
Two vulnerable runs produced the same general protection fault in
plist_del(), after 471 and 91 completed trials. The locking fix completed
two 10,000-trial runs without an Oops, panic, warning or payload signature.
The virtual provider setup and FIFO assignment require privilege. The IIO
read, signal handling and futex operations run as uid 65534 without
effective capabilities. No physical-device or normal-priority hit was
tested.
A source reproducer, kernel configuration, complete serial logs and the
vulnerable/fixed result table are available at:
https://github.com/kimaiden1984-boop/linux-kernel-poc-collections/tree/main/cases/hid-sensor-quaternion-root-a
Fixes: f784fcea4506 ("HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/r/20260610083849.067A11F00893@smtp.kernel.org/
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Yibo Tan <lhfff@tju.edu.cn>
---
drivers/hid/hid-sensor-hub.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/hid/hid-sensor-hub.c b/drivers/hid/hid-sensor-hub.c
index 6470a290ebfc..80f18aff6f1f 100644
--- a/drivers/hid/hid-sensor-hub.c
+++ b/drivers/hid/hid-sensor-hub.c
@@ -335,7 +335,9 @@ int sensor_hub_input_attr_read_values(struct hid_sensor_hub_device *hsdev,
else if (cycles < 0)
ret = cycles;
+ spin_lock_irqsave(&data->lock, flags);
hsdev->pending.status = false;
+ spin_unlock_irqrestore(&data->lock, flags);
}
mutex_unlock(hsdev->mutex_ptr);
--
2.39.5
next reply other threads:[~2026-09-10 11:23 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 11:23 Yibo Tan [this message]
2026-09-10 11:35 ` [PATCH v1] HID: sensor-hub: synchronize multi-value read cancellation sashiko-bot
2026-09-10 15:32 ` Andy Shevchenko
2026-09-10 18:28 ` srinivas pandruvada
2026-09-11 5:16 ` Zhang, Lixu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910112338.4171983-1-lhfff@tju.edu.cn \
--to=lhfff@tju.edu.cn \
--cc=andriy.shevchenko@intel.com \
--cc=bentiss@kernel.org \
--cc=jic23@kernel.org \
--cc=jikos@kernel.org \
--cc=linux-iio@vger.kernel.org \
--cc=linux-input@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lixu.zhang@intel.com \
--cc=srinivas.pandruvada@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox