From nobody Sat Jul 25 21:21:08 2026 Received: from mail-pf1-f172.google.com (mail-pf1-f172.google.com [209.85.210.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6D6AF42EEA3 for ; Mon, 13 Jul 2026 13:26:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783949188; cv=none; b=n0yl1bSVU/3166aGMevRUYQXWPmR1oM4VX9Q6/8sjYFq9DiJll6R4uu4SFRR/gdDqgb69UMHOv/9NzFF8K/VkgPUIOodtbxSAD5CQaBKCCJPG8ZSIcvdSqsgZmaht+mlbFSKfpZf7uHSGAPdyiQphqj0p7fzbX4IOsANT+RG+c0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783949188; c=relaxed/simple; bh=PRXrMhHHmPDmSfezdWtwj6oy53snFDFPa7g4fqzcLx0=; h=From:To:Subject:Date:Message-ID:MIME-Version; b=th7TuNBs7+GGcu3l81+kjaMnMwzEil1EC47ALKTg4pREwW4W6x0WRL4cilye80XukcDuwjsd2XiWrD9nL7/90UmTWc2Xhl2yfCfx2yjsQHm+N36PqEkEgjumh5c7AqR8hlj1Ey1fjtSGpxU++ifdiW8i/hnWioNhpDS5NVxQCgU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SR2Kk1YX; arc=none smtp.client-ip=209.85.210.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SR2Kk1YX" Received: by mail-pf1-f172.google.com with SMTP id d2e1a72fcca58-848595b338cso3580214b3a.0 for ; Mon, 13 Jul 2026 06:26:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783949186; x=1784553986; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=PZo/QGvD29siNmPQnaA3AO4F48nI154SXJ006XgsWpM=; b=SR2Kk1YXNBm1tGnrfvyMJj89tVKe1cFJa4mAAPFj/dHT2BGIrnYKG4BD0nyDyDXvGu mfs3claoYKjHTfdHWW7sfFIU3h6eYftAG//2Ps4g3upiX6gxkyr05+hLH5hnJP5PtmuV /sBN03wPlEkB6hbe2JFNJMpitYtFO1Ylr0pI7VIxJFWb4vn261ZQjD5+U8nbVAqgDIiL BskYlcgep0NA3CtjHh61mF+KHyNVwhevLnbRK3y8cTqNeg3PTk0nN4dISzbMibsxfbDS 9Yu9iNQ2GiP5JmmhKLyLcCqvV348jxiF9lgfKEy6b1EZkXszr7H7NjktYBmJISchC6iG 32/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783949186; x=1784553986; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=PZo/QGvD29siNmPQnaA3AO4F48nI154SXJ006XgsWpM=; b=P94XXF2ww2XbJTNfsLirzvlCG7fhPAXxkGUe3XZec81LocwcbfQBrnI7oKuSLw+8lv Yxl/5JVb95hUpxs3E7aYtBrkLSqvgGhrBCTPgDyCy6fAD8hnHAGFoSf8gEhMwgs+IRIb Dy93d5FYI3iyIZSGQQJYsBS3dlfayoTrEusUISiPw73QAVDL/MyDXe3NzMFknB5FAnhQ 7Cu5/htIR2YMMF199TT/ArdFS0E10VnbVUgrsekXGxMfguMDTwEvRRPg14ALLlHqQdph pqRW9umS2bN/QtxG/yD76c1SgTrV604wmqyDTUEDbkvvy8fCMPGMUo6jToMoafVc73Wh BYcg== X-Forwarded-Encrypted: i=1; AHgh+RoJU87pKSBVra+KtG21yl0vOUAYx+AWB2c2NbEpiFEXZMtwTeUqFFoxTfNe1zTNL2k+acDFiy8zBxYBBD8=@vger.kernel.org X-Gm-Message-State: AOJu0YyW1x5Dx7lIHYqGZBxwN6Acmj5zeutBvG7EhHWD0PMR0a8puGbZ I/vbnH5H8yAbCmbxTNQMW2OHjWj1VsjJK9G4JMKPU5Yv507pCoi3TQT2 X-Gm-Gg: AfdE7cnSDG8U7TOMI6VVvp0Zn6YRsA7A1G8q6bR4XvIwrIdT7oA8cjFlgogNjZH3MwH 6ARZmIoTJcbyvSo5O5AwcBQn2M+Q2YAxEdVwFrCo5KRKIt1GYx8u1za0erqzfDQnqbMAQSnYml2 dXbvqJu9Fy2FPyzFVYMYdIZ8ugaT+HIfDEjKwvAlxjuDM+p6/Xz2J414Jfa6Z6fFaTSjxgwm/Jj bw/xdyiOuvsQxtbQEl0lrDA4D6GFsFdo9SIGtkGCZwdW4adM9eHJQNSnlKXTu+6asl+Iz7z9NHO CdIHV4I72pjLNtD0Q/RZhTBnqIdsStw+AnKNS0IBfJo2ZChejoRWZKyBu2d5B8LtwapzgVPKd0l WIrPCp3t/yhi2UOOQXidUC1gp5K/HG8D8dAMoWhfmzgehDZBugfwiPz8KOeI1XiYGZ4xmelYIZO d2rZ0zTJBnkQ== X-Received: by 2002:a05:6a00:9094:b0:845:d274:bf8a with SMTP id d2e1a72fcca58-8488977e8eamr8992840b3a.51.1783949185747; Mon, 13 Jul 2026 06:26:25 -0700 (PDT) Received: from lgs.. ([101.76.249.46]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6d4d000sm14194934b3a.34.2026.07.13.06.26.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 06:26:25 -0700 (PDT) From: Guangshuo Li To: Jiri Kosina , Benjamin Tissoires , Greg Kroah-Hartman , Alexei Starovoitov , Johan Hovold , Guangshuo Li , Puranjay Mohan , Kees Cook , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, bpf@vger.kernel.org Subject: [PATCH v2] HID: bpf: Fix signedness bug in hid_bpf_hw_request Date: Mon, 13 Jul 2026 21:26:08 +0800 Message-ID: <20260713132608.1265541-1-lgs201920130244@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hid_bpf_hw_request() clamps the return value of hid_hw_raw_request() to the size of the caller-supplied buffer before copying data back to the BPF buffer. However, ret is signed while size is unsigned. If hid_hw_raw_request() returns a negative error code, the comparison promotes ret to size_t. This makes the negative value look like a very large positive value, so the error is clamped to size. The following memcpy() then treats the failed request as a successful transfer and copies stale data back to the caller. Handle negative return values before comparing ret with size and jump to the common cleanup path on error. This preserves negative error codes while still preventing oversized successful returns from overflowing the caller-supplied buffer. Fixes: 2b658c1c442e ("HID: bpf: prevent buffer overflow in hid_hw_request") Signed-off-by: Guangshuo Li Reviewed-by: Emil Tsalapatis --- v2: - Handle negative return values before comparing the return length with the unsigned buffer size, as suggested by Emil Tsalapatis. - Use the common cleanup path for negative return values. drivers/hid/bpf/hid_bpf_dispatch.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/hid/bpf/hid_bpf_dispatch.c b/drivers/hid/bpf/hid_bpf_d= ispatch.c index d0130658091b..520b8f56a514 100644 --- a/drivers/hid/bpf/hid_bpf_dispatch.c +++ b/drivers/hid/bpf/hid_bpf_dispatch.c @@ -445,12 +445,14 @@ hid_bpf_hw_request(struct hid_bpf_ctx *ctx, __u8 *buf= , size_t buf__sz, reqtype, (u64)(long)ctx, true); /* prevent infinite recursions */ - + if (ret < 0) + goto done; if (ret > size) ret =3D size; if (ret > 0) memcpy(buf, dma_data, ret); =20 +done: kfree(dma_data); return ret; } --=20 2.43.0