From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 91A3C519E12; Wed, 30 Sep 2026 17:33:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789640; cv=none; b=sighCgjOFEpr2iFw6bEU5SspQfHli0BSkIF3okxK8qz22qiY86JJb1TiJ6CMZ0W9aQMdFQI0XSlr5VamaYldDNtuB84FNSi7iVA+uGi1h7VHMID4ElZeYhtkoBztmUlRdc4jcXfSsQRTSO2OEOoIoWtYc7Uxpa2LYaZ2roIgnaY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789640; c=relaxed/simple; bh=K7mwAtllseLmoRDuM0pOIx0I+FyYetVBKLXXrJGHm5g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=RWXHTYw1kAXIeEPXgSSQ7sHKbLXb26E57kR/Rm0v/dFJy27Raa3PPFtEgH5g4CN+kurl4UOy8EY9QD9rXLQCYeo9Zy/l4wrYsV2dMj7ht3eGMsFBv3tJ9RL0TKD5vJt1QIfrhY1usowcaKO+nIU2ik82KOgl0l8jcwTO6CVE2LU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=XMEvGmeT; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="XMEvGmeT" Received: by smtp.kernel.org (Postfix) with ESMTPSA id EB9391F000FF; Wed, 30 Sep 2026 17:33:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789638; bh=u4OIDEbwQsLe/rBSN4BTnJesyQLPWKA0rg3UCKostw4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XMEvGmeTOWxS+dEYyfH13equw7ogD4yNpi7IEM5GjPzYcNpBxZbMA8iLAnTFwFY7g FAxkUeUgRSfUVwZJnZhBxV9d7qKXu8x/ygZajdTTFsooIbPKcH3te/UISKlgXXXJMC nh0Waz0J1mmEgdCYnRVf4s8KV+Zrm/0oUyPKwrnI= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Jason Gerecke , Wei Jie Law <98lawweijie@gmail.com>, Jason Gerecke , Jiri Kosina Subject: [PATCH 6.12 503/877] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Date: Wed, 30 Sep 2026 17:23:34 +0200 Message-ID: <20260930152425.516987898@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Wei Jie LAW <98lawweijie@gmail.com> commit 9aa237cf66495b2426ddde8532e9b08a0ed83aaa upstream. The 'wacom_wac_pen_serial_enforce()' function may calculate and pass an invalid offset to hid_field_extract(), resulting in memory reads at incorrect addresses -- possibly beyond the end of the report. If a field in the HID descriptor lists more usages than its Report Count actually reserves space for, the function's inner 'j' will walk past the end of the field: for (i = 0; i < report->maxfield; i++) { for (j = 0; j < report->field[i]->maxusage; j++) { ... value = hid_field_extract(hdev, raw_data + 1, offset + j * size, size); A descriptor listing 12288 usages against Report Count 1 has the loop extract the usage at index 12287 from bit offset 98296 -- about 12 KB past a 2-byte received report. The value is stored in wacom_wac->serial[0] and can reach userspace as an MSC_SERIAL event, making this an information disclosure. Clamp the loop to field->report_count, the number of value slots the report holds. Value slots past the last declared usage are still scanned; they reuse that usage (HID 1.11, 6.2.2.8). Verified on v6.12.105 with a UHID reproducer: a 2-byte report from such a descriptor trips KASAN before the patch and not after it. Fixes: 83417206427b ("HID: wacom: Queue events with missing type/serial data for later processing") Suggested-by: Jason Gerecke Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Assisted-by: GLM:glm-5.3 Signed-off-by: Wei Jie Law <98lawweijie@gmail.com> Reviewed-by: Jason Gerecke Signed-off-by: Jiri Kosina Signed-off-by: Greg Kroah-Hartman --- drivers/hid/wacom_sys.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) --- a/drivers/hid/wacom_sys.c +++ b/drivers/hid/wacom_sys.c @@ -97,8 +97,9 @@ static int wacom_wac_pen_serial_enforce( /* Queue events which have invalid tool type or serial number */ for (i = 0; i < report->maxfield; i++) { - for (j = 0; j < report->field[i]->maxusage; j++) { - struct hid_field *field = report->field[i]; + struct hid_field *field = report->field[i]; + + for (j = 0; j < field->report_count; j++) { struct hid_usage *usage = &field->usage[j]; unsigned int equivalent_usage = wacom_equivalent_usage(usage->hid); unsigned int offset;