From nobody Fri Sep 25 20:47:53 2026 Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B5DEB59D620 for ; Tue, 8 Sep 2026 20:07:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788898026; cv=none; b=KAp9AdfhckX8JG2t4+CTFuUjhkV+BeSjdsIWxczYqYENJTX6M4zHgfIfEwHYjE7y6Oyi5fFc9MSKogAbR7qhdXI30Z2jJZSLNDuyIjFD6rmDv8zSdO5bWJH945wmU982bBVD3H1KgaBvfpF0yEknhxJKgiTE4D3LgqX7UzCSHC0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788898026; c=relaxed/simple; bh=aWhvoKxzbfaU56wQB/QeQ6Ph5VkCnhZCfLmq+NV2GOI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=s6fW2etya8/d4TcrAF8sdjt/BR89VmGuEwTTS6sM/FxVUe/nSNrcOtWAcGry1zS03Ou+hMLtPQa9ueaAaoKJhQ9dy+A+OHcif1akakLFpvBEOYa0CoJwvAMyFeUfFmxpnpp1KCawq0y1zSTDlUZGWsjuNKf+hw0DR26/bHHvkcI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gy8NCtPG; arc=none smtp.client-ip=209.85.128.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gy8NCtPG" Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-4957eefd361so39889635e9.1 for ; Tue, 08 Sep 2026 13:07:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788898022; x=1789502822; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=GzN6rbmR1iUu2LnxWgQWrLFKGnzUpRCvYGe9UsoaA/A=; b=gy8NCtPGL7lvdop/lotLGXYzhHH2rs3WyH8a4NubjS29KXnNRmazshr9AfkhBBSmAV wNTDG6bx5ZlRvfuz9UAxTQwGzZnnqatKaLIHSNrxJSXtFtAOkJSbrWnrq5LN1EfH/39f y977rGwrCVP21AHESkk8tMVN1daqU18jQNbASM9bIYgF1QGxsvFVIlGE54SNpdOaCX/R q01bv5FO0rOBKJoL2uOUNNMGBcV2BgoC9wNawsCSjPxaKFeN+iH0rNwrVSG6zlbIgE90 isBQV5yYg8zKy7F8vfZhB+DgQaYBWLCV0XpjyOwCLg2jK3TCE5q/JNd9XKrTkPhsOVtc Uu9A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788898022; x=1789502822; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GzN6rbmR1iUu2LnxWgQWrLFKGnzUpRCvYGe9UsoaA/A=; b=Ca1bIrna8cBRCIsPi6oIFdMv5e5gk0lbsMMeyAhSPvRpsz7CR+48yklP9NrUnLIvHV 7fZvmodI6XeZJdNieCUEc9ZjXoE99imSdez4SvwHQe7t8IpFXhGTI+hkmxjilU5cWonF +L9uwlZdrywLlE0btOObgF33sSYC25Vfcwfo/HqVTvbJ1QAxMlDT2fTVrlabtk6EP4fs vNN0ryv9pDeMVwGJraSFZpH2EA+tkYgab5t/b7t1Ozc4PfqZITDTr6I/q/8/h5AcTm/x CpNSwy9sawjLRfd4e4gsA6zdqDxiftQwGFAXtEReLmzjkbM64egHa9ewxe+IX8PZi3Cz aw5A== X-Forwarded-Encrypted: i=1; AKwUvByA69dgW6xQ6DochNgTJzvqWibY7WK63BFCC7I0RFGgQBy9QvnhyTs27i0RlwzPfs6T0rO3DEtDbXPKFBw=@vger.kernel.org X-Gm-Message-State: AFuF++mNt5KELgh5Zp8vjrPqixSiXlNzjqeUEEXG+bQE9dbFOHHjRUCm J8/emqiI17dRf273ZG213GQOTeOSdICMMFL5UIK+2aE+5Jf/eYpmDIZc7NxPG87W X-Gm-Gg: AYBFou2oJjpKLhTQEUtYwCgpvJbw7KUHn8EByIogw9VR2PYwd1+qdsNV5nwkzJlmbKr Jn0TO5+njWuepwjswNXEucy4wpAKJVSgcR6RM8LBqrR/1Bi9eJo6KMkIVaeS1xU6tAcbLC5MpoU Eh3Z28eLw/c3loqV3B3hl4fjdzxMtW/14eFwr56EXA800+N1Tl1jCM2K81VRr9RRi5TBDLzj6Q9 Ab31ZlWsk7agkpMnWb/M/yU+/ThWtE1UKTX0vskoSGFaFP+HlaF2+KwNf/gzDLgqbWJUvX12TQO Uf1Gaj0ijSrjPQgk2bNpVcWL4yX5E2FxJltaPPnH7RVrRs4frI7/0S60CP+bbhoWfYaeTlN8gQi fhMiAqWA8KcXv6bQrn/kf1Y34mCTvdGSBSaJ0FFIn2oc6BVAaOklWECiW4i2BmOHM2/N7/yBpoX KjotaivNx60jxIbcGpMdu6AgMt6pe9jrnG+L/cynzVVzel9t8GgJx9qBnT8IHvwgiIJd9V4I9nU vdN8YUlEuv+9D2nC2UNqTYQEd9V6JEFOH94W0KwJ7ukvl7tL0omMC3LTpyNhDAVVorwk2m0vVmz F8p1MdsT9xA4262F3ImVWtLxVJpIGgvSjLyIkraXh2/JtUpNJhiWi9SJYxjLQw== X-Received: by 2002:a05:600c:1d08:b0:49b:96a0:5c00 with SMTP id 5b1f17b1804b1-49cf825168cmr334965715e9.13.1788898022462; Tue, 08 Sep 2026 13:07:02 -0700 (PDT) Received: from xenia15 (30.21.143.157.bbcs.as8758.net. [157.143.21.30]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cfbe5b252sm365683295e9.3.2026.09.08.13.07.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 13:07:02 -0700 (PDT) From: Nazarii Tupitsa To: Jiri Kosina , Benjamin Tissoires Cc: Ping Cheng , Peter Hutterer , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] HID: core: Avoid leaking field ordering on repeated connect Date: Wed, 9 Sep 2026 00:06:55 +0400 Message-ID: <20260908200655.139098-1-nazarii.tupitsa@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hid_connect() builds report->field_entries for every input report. Some drivers stop and restart the same parsed HID device. Wacom wireless does this when the connected tablet changes. Each subsequent hid_connect() overwrites field_entries and leaks the previous allocation. No physical Wacom device was available, so the reproducer was built with a Raspberry Pi Pico. It emulates the affected wireless receiver lifecycle and repeats the tablet connect/disconnect sequence. The ordering is owned by the parsed struct hid_report and remains valid until hid_free_report() destroys the report. Skip initialization when the ordering has already been built. If allocation fails, field_entries remains NULL so a later connect can retry. On Linux 7.2.3, the Pico emulated a Wacom 056a:0084 wireless receiver. An unpatched run with repeated tablet connect/disconnect cycles left multiple unreferenced 512-byte allocations in a kmemleak scan. With this change, repeated cycles successfully recreated the Pen, Pad and Finger devices, and scans after removing the receiver found no leaks. A representative kmemleak entry was: unreferenced object (size 512): backtrace: __kmalloc_noprof hid_connect hid_hw_start wacom_parse_and_register [wacom] wacom_wireless_work [wacom] Fixes: 22f4b026c3dd ("HID: compute an ordered list of input fields to proce= ss") Cc: stable@vger.kernel.org Assisted-by: Codex:GPT-5 Signed-off-by: Nazarii Tupitsa --- drivers/hid/hid-core.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c index a3ff0514f..9f4ba5f60 100644 --- a/drivers/hid/hid-core.c +++ b/drivers/hid/hid-core.c @@ -1802,6 +1802,9 @@ static void hid_report_process_ordering(struct hid_de= vice *hid, unsigned int a, u, usages; unsigned int count =3D 0; =20 + if (report->field_entries) + return; + /* count the number of individual fields in the report */ for (a =3D 0; a < report->maxfield; a++) { field =3D report->field[a]; base-commit: 23da087d9a636d9b2046f3aa3b7470ae51b89c8a --=20 2.50.1