From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f178.google.com (mail-pg1-f178.google.com [209.85.215.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 258DF33FE33 for ; Mon, 3 Aug 2026 16:23:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785774210; cv=none; b=ni7aFJpiVIKms3xZIkU2uHl+qNR/D9JJGTWK/pxgvRbLU8Aj0wogA4Z8hfGa8ssQmtliMo0sGC5i4jcqukqq3wMuJ6uc/GDGejVp2n1kvSSksNsNA+Vi3ckutaRzp4J6sMlYmyGYOsnIs/6Jd5aqcYLNSqh+752jZifXHo7t9Ng= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785774210; c=relaxed/simple; bh=+E+dovH20Z3BzIx6gDwowX8vcV9ujxhqvh6i4kCrDSs=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=MRzekJhXo5BXlA95IAAVZi7HL4U66xtv6Fev4PpyyA9tr5nUE9CqcwsWUpCbamCVNMD/DegFCpoBCKb8n2h4pNj46EKOTw3vRnSbfKdVK2X3rg/z3icmWe+UFSSFojkQyUEO9edZmB8uUiC3aQXBxdLLo7IH8ztCIXjiJSxs2Tc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=crWDDFtA; arc=none smtp.client-ip=209.85.215.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="crWDDFtA" Received: by mail-pg1-f178.google.com with SMTP id 41be03b00d2f7-cbe3fed2f58so1897609a12.3 for ; Mon, 03 Aug 2026 09:23:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785774208; x=1786379008; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=/MCvJOFJV8ipMWE62yWISNasmONj7SWa3jUTj8zprYQ=; b=crWDDFtAQ2L2+KZIMLsl4mUE36nQqJBF+nI1XKUzvBo3fnqwFW3HJEeGkbKq+j1Eo9 MVRgGpKG6QdeQLpGuleniQu+GNG76uZGSU0aPAr98qBcYjX6EIMGN15XUbJ8z6uuKl8z QKt3vUZ7j64gTJXfhr5pP8IKlJMILd75N1f8DAW0kIQ4FyHPxoQEZ7utnyiAmhatRizr 7oHrhq2JvEnfWfZzEUJxzU/OPz1vjUJnCgPGHfdhA2dZK2CNq3xJc3ArjC4o9SZnO45g fQDggfQSvNDgJSALfCf/i6zjlUY/F9pJLpiLg1sxWkVhkeUBfuFnLOmcf2Phzo6FzBtc gdBg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785774208; x=1786379008; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=/MCvJOFJV8ipMWE62yWISNasmONj7SWa3jUTj8zprYQ=; b=lGxSkiz4kFb2x50TpnTyGQyTxVSaugKU/QRtYIbJHNsJuco4TyekY1h6SBbu5MMfZQ Ip7kPW0F+Xt3uIGcXBFzpQqSeSgZPpMtz0TaWI9qPjcTc5ekn2VL4gaZrLiHKnFo7DYE 5s5MKRUqz0SXWI6V9DxykkkEecJ3VbBPp2Ds26lAjqLW5VBB1S+gGEsMVRwoo3wXI1mm EYu2afc5SkK0/2oNgLCaC04FMvkP9mP+8TbOdkPEx774Mi16oltf8LjveDWGVRY9gflf x1QNDDgAl4c1v5spE/9i7Ut2GQz+SBwJHaZKUUXwB0XhSafPzKk1jaCSHi0AFjQQ72wd 4q2w== X-Forwarded-Encrypted: i=1; AHgh+RrDCvJ/eetLS249qLBwjFB0TzZRoATW8IoAjww6fGcON8EJpt3GEKAZ0u4PvaQxzyHcJl69eFysdhm9iDg=@vger.kernel.org X-Gm-Message-State: AOJu0Yy8qf2H1Y+tbgaITgQcX4Hri0vmaVT+YqAss9a58gPuW58kXqkk CASJMUngsGHnXF0t2L77/MA1zt5wgM82b778TqS9kDcsJ5MkNBQJ0W0SodvsjQ== X-Gm-Gg: AR+sD10KraNjJ3vyVuL9GwkHYF9ldDN7fMo65i4oAYWBUzI1mgKk4qU0lyCaMyInlaZ /C4JHYJOJYaYuKdfJtpxlCYdHlqiMOmWVc1+WSA4rGP70GpuRC6XM7D3YGCm13qxIKkzym+WwVh L+lguTUo7OFbGedihhHtbRlDvCi22GmxrSNA6wJzxV5c44Tw+Yypkjd3gghgMPnDqwWCsFlDqcZ vebhFrvVnZTn+cnkxq4TKTSW6HIFhAAFbh+IU+y/Bfj2+KjknfO9RStVO9WKJX3PYiQYOjYYbni QIvyRPGOFrcVJwN+LulE8L14RHbbGpfLHwiaA/+zIoM2oDSDzYF5nGGAD9fZ2ZcVYbXDlYDsgQi xEtDpiJfmL2eB2NtL+SA3cohfiOTZFcBLBopYAclEZbfdOt+bW+9PW7rrvMuOtoPS4q8mYJsKc/ ubG1cLBnubTv6Z4gyUEA6LiscbhZ+0Q+2Ek751Iier9vpXrJYS6F45g3ILWl+xTbM5ttxMR/biH SCeIY5G7hYQfkMlGFSQJ3QwUsylmHk= X-Received: by 2002:a05:6a20:6a06:b0:3c6:61b9:917c with SMTP id adf61e73a8af0-3c92a518b1emr9469376637.11.1785774208484; Mon, 03 Aug 2026 09:23:28 -0700 (PDT) Received: from google.com ([2a00:79e0:2ebe:8:4fff:876c:cdae:e53c]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd4e47dsm58242974eec.3.2026.08.03.09.23.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 09:23:27 -0700 (PDT) Date: Mon, 3 Aug 2026 09:23:25 -0700 From: Dmitry Torokhov To: Griffin Kroah-Hartman Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Ingo Molnar , Greg Kroah-Hartman Subject: Re: [PATCH 1/3] Input: xpad - add safer data access framework Message-ID: References: <20260803-xpadone_packet_fix-v1-0-280da203f15c@kroah.com> <20260803-xpadone_packet_fix-v1-1-280da203f15c@kroah.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260803-xpadone_packet_fix-v1-1-280da203f15c@kroah.com> Hi Griffin, On Mon, Aug 03, 2026 at 05:07:24PM +0200, Griffin Kroah-Hartman wrote: > USB xpad devices could send short messages which would cause reads and > writes outside of the data buffer. > > Fix this by adding the safe_data struct and the sdata_check() function when > accessing packet data for input events, and add the usage of this to > xpadone_process_packet(), which was vulnerable to OOB reads/writes. > > Suggested-by: Ingo Molnar > Suggested-by: Greg Kroah-Hartman > Signed-off-by: Griffin Kroah-Hartman > --- > drivers/input/joystick/xpad.c | 115 ++++++++++++++++++++++++++---------------- > 1 file changed, 71 insertions(+), 44 deletions(-) > > diff --git a/drivers/input/joystick/xpad.c b/drivers/input/joystick/xpad.c > index feb8f368f834..c516860711a8 100644 > --- a/drivers/input/joystick/xpad.c > +++ b/drivers/input/joystick/xpad.c > @@ -780,6 +780,24 @@ struct usb_xpad { > bool delayed_init_done; > }; > > +struct safe_data { > + unsigned char *data; > + u32 len; > +}; > + > +/* > + * Safe Data Check > + * > + * Returns the correct data when inside the array's bounds, > + * returns 0 when accessing an out-of-bounds index. > + */ > +static u8 sdata_check(struct safe_data *sdata, int idx) > +{ > + if (idx >= sdata->len) > + return 0; > + return sdata->data[idx]; > +} I'd rather we had explicit length checks for various packets and skipped the processing if the packet is short instead of making large number of what can be considered repeated checks. Thanks. -- Dmitry