From nobody Sat Jul 25 19:29:02 2026 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BE083448CF6 for ; Tue, 14 Jul 2026 14:25:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784039112; cv=none; b=UQR6LLLPzRvlPwaAJntuJKvXT6klS5MWOLWYhonZkh0WkLYyBpRNh8jgOGTa1Wjid+gsjjXh5wLLontmL51LufnpLe+OjGSyE9+OExv0umq2KkrgZGlAGdmj7cx7mQFdCj4fhEZ4rt2eir0uqC6zzsdpzXLE/ofoRnOpGJtEE1M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784039112; c=relaxed/simple; bh=IK3LCy68nNia2gEMkKnq6We11pVBGa+uglDzb2BQn0A=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HRPxLmmjf2YQfGnSePSuq13f7fFsOV6QSmODj8YkuNPwdhimN7yL9AMJoasyr1RxZLZ0rZ+B5ynNJtspb3+3Fk47TgNkdHRrATOpSSLJrBiZrJ2xrn+YRB+QJ9Fa6Wrxsq0w+lGGwsLwNGzRQ5mJtL9YZVAWKhPrEpH4IdOsZm4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=TZIvveBF; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="TZIvveBF" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-493f0ae9572so17882875e9.3 for ; Tue, 14 Jul 2026 07:25:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1784039108; x=1784643908; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=jcfrg6EgnjJunuXszKnS5dRMOUov45ln2QkWfO7ihtI=; b=TZIvveBFvGvE8FBiW5rVXisexkGUyXphLa1Wmmw1YpygomAI61AYJA0mrDvbOij1Vh sVp+iyJdxLyxXQvvRXrqCMLTeofV79eGv0wUuiBpGMVvWIzsWOVor9+i5P7DzbRHYw4v 87PUatCIn1vGZhDKG/gPJ6ZCNb7n+rO8ugRjoGKhJe24SgoR4xrPBnXbPPQcjtLGiKYp UrfPP/vOIj/H8jpF8O+hS6+HFCl4rBOAMLZZoMWaKGG9NGcqewhBVQu1cqPhifyehLvk 8RztKZ1kQC4oAjlmtmdbsiW3xjvVY+fGl89ft3RlDKdgj+B3bAgVYkA9cTdcqGoIiNdj kJNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784039108; x=1784643908; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jcfrg6EgnjJunuXszKnS5dRMOUov45ln2QkWfO7ihtI=; b=nSgoP/O/l5WT0lj4qcHa3S7vcFrZRBv0zcpt5YI2EEEUgFLJaNiE4WsPdCIdEG2itn /L9GehRJi8bMzYAny+GfqsnVMfopZ3swk9ZozrUTH7VVO7f0p5FTQJlE41zuVRp7qJxV wDsaGYLBFeItEB3xyWW3Gcwu8Lq6F+gyEwVK8Zqkpq5Co35MhYgbbTqFIDYkFj88OhPC JWkJyJA0kZZiPaeqEMl/TcuG2+roQK43VF6EsQ0BRpcZBApX2+taE5kTM6j2Ib4JOWHf FPY/ONbdJfbsitTu80fBHgs6NAPtL9OOGkvQXlk8dC3+lh/C1oRln1xxQWBqOjzVDrXv wjow== X-Forwarded-Encrypted: i=1; AHgh+RqAF9lGQ6oRV3D6iGdnS66itN5oIcnicscBROY6iKDNt33UE2G9EfTB3AgsBNeON5EwsVXBB+n3Q78cFYI=@vger.kernel.org X-Gm-Message-State: AOJu0YxB5bbZmqU7MAPiMZ95zYeEoD7VLOdOewhLZfA3SpPEy9jCALWV Llb5XjJJ4sJK1SgcY6f5g8xNlpzzSpJWGiOHrnXSl6ZroA1NTw5iDsrQuDuHIIQ53jHQnrcK09M wn9FbFngl X-Gm-Gg: AfdE7clDCpckDyCUITEpc1y4B1Yi9jXXg/R2T49hayJig8z1iHvHA4R5F5B7Ksf48WV lmudqzlX9RVAow6jLVP0Va0ey0ZFc08hQ5QBOC6+QKsbQEGfv/zHgJAjFoRyWSKYJvgEkNFdrRt RHiLtm7yUgFNnwBA+Gzqzx3fp0rCdeFuUAFevr6Pl6ERhA/keHQ7olBk/WQ1EeE1VuY3TjJv9Pz WTnyMdkwf/T6XuUd5IEdFJq1m0s0g9R75xjZVLJTiZnfuekEkyna74H5zwaMOAuhiTMnkzrjDCk adoZpIlQ+PpR1gbEhPXMwa2Uvc4qlZj9CKZK42VJqCIocAetrtKYS5SmKZoMbIgCmFp5X3OQEc9 oPy9cKs+p11nfhish7UmECyGQbYCJYte0LOtTP8TOXroLMWrTJhQRtLaRALPfpEa4xdA92nGZ2b OXx6nEq3i8v9AmWFbHjcsYk4rzC0knuZ4+5LLz/Jj3zDjAOKhLKtdfLx5iKpBi+h056rUD9/YWd RwGPmMsSLuZPseHfj82+/l1HAWfa95jcW2cVgBIdinXJw== X-Received: by 2002:a05:600c:4fc6:b0:493:e52f:6ee1 with SMTP id 5b1f17b1804b1-493f8784bb5mr151350735e9.0.1784039107888; Tue, 14 Jul 2026 07:25:07 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.188]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4950a2ed840sm74518925e9.10.2026.07.14.07.25.06 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 14 Jul 2026 07:25:07 -0700 (PDT) From: Doruk Tan Ozturk To: Jiri Kosina , Benjamin Tissoires Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] HID: uclogic: Clear stale pen_input pointer on partial input registration Date: Tue, 14 Jul 2026 16:25:05 +0200 Message-ID: <20260714142505.95630-1-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" uclogic_input_configured() caches the pen input_dev in drvdata->pen_input before input_register_device() is called for it. The in-range timeout handler uclogic_inrange_timeout() later dereferences this pointer, guarded only by a NULL check. If hidinput_connect() fails while bringing up the HID inputs (e.g. an input_register_device() failure, or an input left unpopulated), it unwinds via hidinput_disconnect() and frees the input_dev, but the driver's cached drvdata->pen_input is not cleared and is left dangling. Because this driver installs a ->raw_event callback and the hidraw interface is claimed, hid_connect() still returns success even though HID input was not claimed, so hid_hw_start() and probe() succeed. The device stays live, and a subsequent in-range pen report re-arms inrange_timer via uclogic_raw_event_pen(). When the timer fires, uclogic_inrange_timeout() dereferences the freed input_dev: the NULL check does not help because the pointer is dangling, not NULL. This is a use-after-free distinct from the timer-teardown case. Clear drvdata->pen_input after hid_hw_start() when HID input was not claimed, so the cached pointer never outlives the input_dev and the existing NULL check in the timeout handler becomes effective. Found by 0sec (https://0sec.ai). Fixes: 01309e29eb95 ("HID: uclogic: Support in-range reporting emulation") Cc: stable@vger.kernel.org Assisted-by: 0sec Signed-off-by: Doruk Tan Ozturk --- drivers/hid/hid-uclogic-core.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/drivers/hid/hid-uclogic-core.c b/drivers/hid/hid-uclogic-core.c index b73f09d26688..396d46b0b88e 100644 --- a/drivers/hid/hid-uclogic-core.c +++ b/drivers/hid/hid-uclogic-core.c @@ -262,6 +262,19 @@ static int uclogic_probe(struct hid_device *hdev, goto failure; } =20 + /* + * hid_hw_start() -> hid_connect() returns success even when + * hidinput_connect() failed, because this driver provides a + * ->raw_event callback and the hidraw interface was claimed. In that + * case the input_dev that ->input_configured() cached in + * drvdata->pen_input has already been freed by hidinput_connect()'s + * error unwinding, leaving a dangling pointer that the in-range timer + * would dereference. Drop it so uclogic_inrange_timeout()'s NULL + * check takes effect. + */ + if (!(hdev->claimed & HID_CLAIMED_INPUT)) + drvdata->pen_input =3D NULL; + return 0; failure: /* Assume "remove" might not be called if "probe" failed */ --=20 2.43.0