The Linux Kernel Mailing List
 help / color / mirror / Atom feed
  • * Re: [PATCH v2 1/1] HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
           [not found] <20260416131655.2279756-1-lee@kernel.org>
           [not found] ` <aeDwkQ-S6QQuK_RL@google.com>
    @ 2026-05-12 15:49 ` Jiri Kosina
      1 sibling, 0 replies; 2+ messages in thread
    From: Jiri Kosina @ 2026-05-12 15:49 UTC (permalink / raw)
      To: Lee Jones; +Cc: Benjamin Tissoires, linux-input, linux-kernel, gnoack
    
    On Thu, 16 Apr 2026, Lee Jones wrote:
    
    > It is currently possible for a malicious or misconfigured USB device to
    > cause an out-of-bounds (OOB) read when submitting reports using
    > DOUBLE_REPORT_ID by specifying a large report length and providing a
    > smaller one.
    > 
    > Let's prevent that by comparing the specified report length with the
    > actual size of the data read in from userspace.  If the actual data
    > length ends up being smaller than specified, we'll politely warn the
    > user and prevent any further processing.
    > 
    > Signed-off-by: Lee Jones <lee@kernel.org>
    > ---
    > v1 => v2: Add more size checks to protect against issues during recursion
    
    Applied, sorry for the delay.
    
    -- 
    Jiri Kosina
    SUSE Labs
    
    
    ^ permalink raw reply	[flat|nested] 2+ messages in thread

  • end of thread, other threads:[~2026-05-12 15:49 UTC | newest]
    
    Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
    -- links below jump to the message on this page --
         [not found] <20260416131655.2279756-1-lee@kernel.org>
         [not found] ` <aeDwkQ-S6QQuK_RL@google.com>
         [not found]   ` <20260430140148.GJ1806155@google.com>
    2026-05-12 14:12     ` [PATCH v2 1/1] HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID Lee Jones
    2026-05-12 15:49 ` Jiri Kosina
    

    This is a public inbox, see mirroring instructions
    for how to clone and mirror all data and code used for this inbox