From: sashiko-bot@kernel.org
To: "Daniel Golle" <daniel@makrotopia.org>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org,
dmitry.torokhov@gmail.com, linux-input@vger.kernel.org,
robh@kernel.org
Subject: Re: [PATCH 3/4] Input: hynitron-cst816x: release gesture keys
Date: Thu, 01 Oct 2026 11:00:06 +0000 [thread overview]
Message-ID: <20261001110007.712101F000FF@smtp.kernel.org> (raw)
In-Reply-To: <6f87a6c44555a0abb5d7f677250c28aacb230fbc.1790851590.git.daniel@makrotopia.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] input: OOB read in cst816x_release_keys() due to unvalidated DT keycodes
--
commit cb8390c95078c2f0098d2be4f937c758b29ad76d
Author: Daniel Golle <daniel@makrotopia.org>
Input: hynitron-cst816x: release gesture keys
The gesture key is reported with the value of the touch flag, so it stays
pressed once the controller stops reporting the gesture code while the
finger is still down. This commit reports the press on its own and releases
the keys the input core still holds down when the first report without a
gesture code arrives.
> diff --git a/drivers/input/touchscreen/hynitron-cst816x.c b/drivers/input/touchscreen/hynitron-cst816x.c
> index 865c5a767ba01..e2093518e8af1 100644
> --- a/drivers/input/touchscreen/hynitron-cst816x.c
> +++ b/drivers/input/touchscreen/hynitron-cst816x.c
[ ... ]
> @@ -168,6 +168,18 @@ static void cst816x_reset(struct cst816x_priv *priv)
> msleep(100);
> }
>
> +static void cst816x_release_keys(struct cst816x_priv *priv)
> +{
> + unsigned int i;
> +
> + for (i = 0; i < priv->keycodemax; i++) {
> + if (!test_bit(priv->keycode[i], priv->input->key))
[Severity: Medium]
Can this read out of bounds on the priv->input->key bitmap?
If a keycode provided in the device tree property exceeds KEY_MAX,
input_set_capability() safely ignores it during registration, but the
invalid large value remains in the priv->keycode array.
When cst816x_release_keys() iterates over this array, it directly calls
test_bit(priv->keycode[i], priv->input->key). Since test_bit() doesn't
perform bounds checking like the input core's event handlers do, passing
an oversized keycode could result in a memory read past the end of the
bitmap structure during touch interrupts.
> + continue;
> +
> + input_report_key(priv->input, priv->keycode[i], 0);
> + }
> +}
> +
--
Sashiko AI review · https://sashiko.dev/#/patchset/d18629ede3f2fd5a08d0cbdaf82f4254e89500ed.1790851590.git.daniel@makrotopia.org?part=3
next prev parent reply other threads:[~2026-10-01 11:00 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 10:52 [PATCH 0/4] Input: hynitron-cst816x: axis properties and gesture keys Daniel Golle
2026-10-01 10:52 ` [PATCH 1/4] dt-bindings: input: touchscreen: hynitron,cst816x: configure axes Daniel Golle
2026-10-01 11:02 ` sashiko-bot
2026-10-01 19:01 ` Conor Dooley
2026-10-01 10:52 ` [PATCH 2/4] Input: hynitron-cst816x: respect touchscreen DT properties Daniel Golle
2026-10-01 10:53 ` [PATCH 3/4] Input: hynitron-cst816x: release gesture keys Daniel Golle
2026-10-01 11:00 ` sashiko-bot [this message]
2026-10-01 10:53 ` [PATCH 4/4] Input: hynitron-cst816x: time out gesture key release Daniel Golle
2026-10-01 11:01 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001110007.712101F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=daniel@makrotopia.org \
--cc=devicetree@vger.kernel.org \
--cc=dmitry.torokhov@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox