From nobody Sat Jul 25 16:48:59 2026 Received: from mail-oa1-f43.google.com (mail-oa1-f43.google.com [209.85.160.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AFCEC3C4544 for ; Wed, 15 Jul 2026 19:59:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784145565; cv=none; b=JNlnKdLFf27B9gXZ8PCQBktLqcQjiVbopYeMKL8BUDEXsHd2J2kebpKYo+hS+V2Y1/DodqHu8SR1In245jyAyJ+KVs3wfXxzsandef68J0+/sjwspeWP11lRyaepUpIV/hqhf8j3jna/ev2EutF5iG9VIumryjpCHAHeBhHU7hE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784145565; c=relaxed/simple; bh=XbyXdxPtzEzK35SBgl6Z8dxuUawkH7HDJP/Pnno1J6Y=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=Z4OtRj42YrQh7wIH36KeZmoSdAzdhbtJ6p55mwUS8U7wOG9WyJwyeKaAI9j8R+acIhiQ5zaFJ5rzeFitOL9NQm7CyGwHyGMSYvRu6LL2ag5DX38nzQc1MWfpbNjl8Cv0Ys91+1XdDe089wzExMyhC/IesYOz6g4DZQYZVPI+EU8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=mCU8RplU; arc=none smtp.client-ip=209.85.160.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="mCU8RplU" Received: by mail-oa1-f43.google.com with SMTP id 586e51a60fabf-43bf9548df4so2940133fac.0 for ; Wed, 15 Jul 2026 12:59:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784145556; x=1784750356; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TjRo1qwaS6KgHldUrjOUU5P6LkI4d5qbPD0QlzsVVeA=; b=mCU8RplUv9NwA/HHT5N/PHfgvTsGKL0NmA6yk1t8kjqmuCOqIgKLN9N0CFrgmA+fQY Jsgcj3LbAWHTHjCG9ho2KhMSocCnlbEHEbLScABP3M+zU7+PRNq61goXbp+af3CVRkat bVO7kj3r4xOgx4TlKv0Cs2+Gq0e9jrmPR+PgHyIPGzbi10E7I1VAouTyJ2eSXhZhhcrN pYTN/WLsIYKdV621ct3SYowiYUsSJYJjPcFZ5amD+MF5bhWy6pxpyQhsvQN2qNJK+yOA bdOQbM66pA3eEQt3JfwVZmwBmqOhb/2tvQJlHdreHAds9/gRSeDCxidkIclWKLck1C7h O9YA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784145556; x=1784750356; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=TjRo1qwaS6KgHldUrjOUU5P6LkI4d5qbPD0QlzsVVeA=; b=Zpehrr01SHf/SEwpssMdGSqmlFg/tOWshdExDB5tHE8VSFAr/dzEa7EcRqSiMSOlgN Fm0PpdE2TNSgm8MdkTGQavcXmGv67JXIysnmB7CJ5ccWmrY+s3Qki2L9rbI1yEVS8tZv uofXP36R006CB67er1J2XaBY73yJAXFd89KZp6hgdvoUTH5gSSdB5psx725X54kMpJo4 ejYEieYZcadewS3ASjmnDVaOlktf8yD6K6IsJKblBjTMlH00hIqwN0Y+NqH4syjno7L0 mvr0SkiLGg1UAt+ocn3Fpaeji9F85alMleEzwGHlhr6sZGXIV0Q99InnAASGfw4F6Sre t5BA== X-Forwarded-Encrypted: i=1; AHgh+RqpEq5WtcOL9IbA5HFvdGnQSQjZ0CIH4db+r8I/mD1F4rJAp6qbG22MjZG8iXxcysgmPWn0h0CcRtHsEng=@vger.kernel.org X-Gm-Message-State: AOJu0YwTWZJv3suW372YQhdvlxEDDuKlReAy0eOaq+mODLQBBV/jVMCl sqTG8pswPAXynqB2dEHYy7Pw8UYUVsAK+QCm6yb3ZBi7J7GBBZwyGNVP X-Gm-Gg: AfdE7clDS+thtkvcvEb6BoUrlf7dsio2fO0YL7SnksiVLU+ToEZ/kgVOC1762OGvzxf VnpliS/uv6DvBN7FBwm+iQZqKiCbsyVEAJjlhd4JVyuKzmfkDsGvGUoE8my0ponjc5tyIjaDzVw 7IZ6SxPRvkKI2GY7eMQzloq9LGb4v3AwZNqHrRyd0zpGqOIbYNJwwRSQqq8FdL2/khjN0Hlb9av Rf+izBx1dfiXDZid8CSN39YGWtxfVjT7bXwBje7RqrFTncH8QEDsckJD0Re6wK0T20Te1ltrWXT AoV6Z+9q8VFtZSrZXf3Vc7x83EoMV3axzaLI76AvlIiv/pmzThQxwYIazlSt39bXjtYLVzzVM6V OCypNH0ybGrCUKFQV/Yd26X7EUgWGsPMITQyGFVVDCFySw/dIDykMGZfIKdyvFjDlQMd+cynEIM 66vI96GtfNksBX X-Received: by 2002:a05:6870:350e:b0:448:549e:7dd4 with SMTP id 586e51a60fabf-4560b4b8e7fmr4034477fac.15.1784145556114; Wed, 15 Jul 2026 12:59:16 -0700 (PDT) Received: from desktop ([2806:2f0:9260:f072:92d3:78b1:9863:130a]) by smtp.gmail.com with ESMTPSA id 586e51a60fabf-45200b7b4c5sm14016799fac.10.2026.07.15.12.59.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 15 Jul 2026 12:59:15 -0700 (PDT) From: =?UTF-8?q?Jose=20Villase=C3=B1or=20Montfort?= To: Jiri Kosina , Benjamin Tissoires Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, =?UTF-8?q?Jose=20Villase=C3=B1or=20Montfort?= Subject: [PATCH] HID: magicmouse: reject devices that bind without an input device Date: Wed, 15 Jul 2026 13:58:53 -0600 Message-ID: <20260715195853.1302765-1-pepemontfort@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable magicmouse_raw_event() and magicmouse_event() dereference msc->input (e.g. input->id.product, and via magicmouse_emit_touch() and magicmouse_emit_buttons()) without checking it for NULL. hid-input only sets msc->input when the device exposes a usable input device. magicmouse_probe() guards against this with an "input not registered" check that fails the probe when msc->input is NULL -- but the USB Magic Mouse 2 / Magic Trackpad 2 path returns 0 before reaching that check. A device that binds this driver on that path (for example a malicious one spoofing an Apple VID/PID) with a report descriptor that does not produce an input device therefore ends up bound with msc->input =3D=3D NULL. A subsequent input report then dereferences the NULL pointer in the ->raw_event / ->event callbacks and panics the kernel. Move the msc->input check ahead of the early return so it covers every bind path. Legitimate devices register an input during hid_hw_start() and are unaffected. Fixes: 0b91b4e4dae6 ("HID: magicmouse: Report battery level over USB") Link: https://lore.kernel.org/linux-input/20260714102540.3EB2E1F000E9@smtp.= kernel.org/ Cc: stable@vger.kernel.org Signed-off-by: Jose Villase=C3=B1or Montfort --- Surfaced by an automated review of Alec Hall's parallel battery series (the Link: above), independent of that work. This is a sibling hardening fix to "HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()" [1], which touches the same driver. I went with fixing the probe path (rejecting a bind without an input) rather than adding per-callback "if (!msc->input) return 0;" guards, since a single check at probe covers both ->raw_event and ->event and addresses the root asymmetry. Happy to switch to per-callback guards if reviewers prefer that. [1] https://lore.kernel.org/linux-input/20260715053526.574725-1-pepemontfor= t@gmail.com/ drivers/hid/hid-magicmouse.c | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/drivers/hid/hid-magicmouse.c b/drivers/hid/hid-magicmouse.c index 97562765a..bd6a12e40 100644 --- a/drivers/hid/hid-magicmouse.c +++ b/drivers/hid/hid-magicmouse.c @@ -923,17 +923,25 @@ static int magicmouse_probe(struct hid_device *hdev, magicmouse_fetch_battery(hdev); } =20 - if (is_usb_magicmouse2(id->vendor, id->product) || - (is_usb_magictrackpad2(id->vendor, id->product) && - hdev->type !=3D HID_TYPE_USBMOUSE)) - return 0; - + /* + * The ->raw_event and ->event callbacks dereference msc->input, which + * hid-input only populates when the device exposes a usable input. + * Reject a device that bound without one -- including on the USB Magic + * Mouse 2 / Trackpad 2 path that returns early below -- so a device + * (e.g. one spoofing an Apple VID/PID) cannot drive those callbacks + * into a NULL pointer dereference. + */ if (!msc->input) { hid_err(hdev, "magicmouse input not registered\n"); ret =3D -ENOMEM; goto err_stop_hw; } =20 + if (is_usb_magicmouse2(id->vendor, id->product) || + (is_usb_magictrackpad2(id->vendor, id->product) && + hdev->type !=3D HID_TYPE_USBMOUSE)) + return 0; + switch (id->product) { case USB_DEVICE_ID_APPLE_MAGICMOUSE: report =3D hid_register_report(hdev, HID_INPUT_REPORT, MOUSE_REPORT_ID, = 0); --=20 2.55.0