From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 15D774E50CF; Wed, 30 Sep 2026 15:58:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790783932; cv=none; b=NxfupJA5j0qZXBEC8uuk//ZDTABRnDBGhTF1stZq4sR6xR2mPSKGoh5wJfaIwQMTA3C1SO620blwhXBKOXVJy1C6fOqC5ml5K3xwEmHppnpjHRQ3/ArvzEdIGolcXb1tbndNpL7gRhxhYf9tWlMhzvcAn/2rl/G7gI8sPj0prk0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790783932; c=relaxed/simple; bh=cEKi4P/rXp4v20GUYi2yFsRNa86TrvOB94OCB80ZjoI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PvKbU6nYbDufUHU/D0bmEbbhrH+wbkillE3EFHQJZzvtMUjtRML+E6WO6WgNNVHxZrzENtM1BUQmHbYvdGWFi8eSyuTg3hUtD+ev6h0i3ztxTbe5Jylr9aGPxq2S5OzVIWoF21QC76y9M64BbkH+Iw6IWgLsZvepq6YWVLiRDqw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=tETSFbp8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="tETSFbp8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 17A6E1F000FF; Wed, 30 Sep 2026 15:58:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790783923; bh=KFp1VlLMb1/ZlMYMZcNmv1FN05ERxx0C8QJ+tMYavHk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=tETSFbp8dqvaD4zq5/FEBhRRDqDnx0oLHQstH/75hoXudcTXajN+59snParBBM3w+ bFIg3bLQR4KeFF1GXnWA3H0GCY93nXft7FTIipma9gGJPQtLfScmA0LToLJhM3YyY2 agBBib1P4nPDygnbAe1heVzBqrogHUz3madYHENU= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Jason Gerecke , Wei Jie Law <98lawweijie@gmail.com>, Jason Gerecke , Jiri Kosina Subject: [PATCH 5.10 570/595] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Date: Wed, 30 Sep 2026 17:27:43 +0200 Message-ID: <20260930152359.983955324@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152347.700140858@linuxfoundation.org> References: <20260930152347.700140858@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Wei Jie LAW <98lawweijie@gmail.com> commit 9aa237cf66495b2426ddde8532e9b08a0ed83aaa upstream. The 'wacom_wac_pen_serial_enforce()' function may calculate and pass an invalid offset to hid_field_extract(), resulting in memory reads at incorrect addresses -- possibly beyond the end of the report. If a field in the HID descriptor lists more usages than its Report Count actually reserves space for, the function's inner 'j' will walk past the end of the field: for (i = 0; i < report->maxfield; i++) { for (j = 0; j < report->field[i]->maxusage; j++) { ... value = hid_field_extract(hdev, raw_data + 1, offset + j * size, size); A descriptor listing 12288 usages against Report Count 1 has the loop extract the usage at index 12287 from bit offset 98296 -- about 12 KB past a 2-byte received report. The value is stored in wacom_wac->serial[0] and can reach userspace as an MSC_SERIAL event, making this an information disclosure. Clamp the loop to field->report_count, the number of value slots the report holds. Value slots past the last declared usage are still scanned; they reuse that usage (HID 1.11, 6.2.2.8). Verified on v6.12.105 with a UHID reproducer: a 2-byte report from such a descriptor trips KASAN before the patch and not after it. Fixes: 83417206427b ("HID: wacom: Queue events with missing type/serial data for later processing") Suggested-by: Jason Gerecke Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Assisted-by: GLM:glm-5.3 Signed-off-by: Wei Jie Law <98lawweijie@gmail.com> Reviewed-by: Jason Gerecke Signed-off-by: Jiri Kosina Signed-off-by: Greg Kroah-Hartman --- drivers/hid/wacom_sys.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) --- a/drivers/hid/wacom_sys.c +++ b/drivers/hid/wacom_sys.c @@ -102,8 +102,9 @@ static int wacom_wac_pen_serial_enforce( /* Queue events which have invalid tool type or serial number */ for (i = 0; i < report->maxfield; i++) { - for (j = 0; j < report->field[i]->maxusage; j++) { - struct hid_field *field = report->field[i]; + struct hid_field *field = report->field[i]; + + for (j = 0; j < field->report_count; j++) { struct hid_usage *usage = &field->usage[j]; unsigned int equivalent_usage = wacom_equivalent_usage(usage->hid); unsigned int offset;