]> exis.tech > repos - linux.git/commit
HID: core: Fix OOB read in hid_get_report for numbered reports
authorLee Jones <lee@kernel.org>
Tue, 16 Jun 2026 11:26:56 +0000 (11:26 +0000)
committerJiri Kosina <jkosina@suse.com>
Mon, 29 Jun 2026 09:10:23 +0000 (11:10 +0200)
commitaf1a9b65ebe8a948eda805c14b78d4d0767cb1b5
treeec2df2bfcf632e15962323dd1d35d75ed895060a
parent0021eb09041f021c079be1022934a280f7f176c0
HID: core: Fix OOB read in hid_get_report for numbered reports

When a caller passes a size of 0 to hid_report_raw_event() for a
numbered report, the function originally called hid_get_report() before
performing any size validation.

Inside hid_get_report(), if the report is numbered (report_enum->numbered
is true), it unconditionally dereferences data[0] to extract the report ID.
With a size of 0, this results in an out-of-bounds read or kernel panic.

Fix this by moving the numbered report size validation check before the
call to hid_get_report(), ensuring that size is at least 1 before
dereferencing the data pointer.

Fixes: 2c85c61d1332 ("HID: pass the buffer size to hid_report_raw_event")
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
drivers/hid/hid-core.c