Skip to content

Commit 6b3014e

Browse files
omnijBenjamin Tissoires
authored andcommitted
HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
wacom_wac_queue_insert() calls kfifo_skip() in a loop when the kfifo doesn't have enough space for the incoming report. If the kfifo is empty, kfifo_skip() reads stale data left in the kmalloc'd buffer via __kfifo_peek_n() and interprets it as a record length, advancing fifo->out by that garbage value. This corrupts the internal kfifo state, causing kfifo_unused() to return a value much larger than the actual buffer size, which bypasses __kfifo_in_r()'s guard: if (len + recsize > kfifo_unused(fifo)) return 0; kfifo_copy_in() then performs an out-of-bounds memcpy, writing up to 3842 bytes past the 256-byte buffer. Add a !kfifo_is_empty() condition to the while loop so kfifo_skip() is never called on an empty fifo, and check the return value of kfifo_in() to reject reports that are too large for the fifo. Suggested-by: Dmitry Torokhov <dmitry.torokhov@gmail.com> Fixes: 5e013ad ("HID: wacom: Remove static WACOM_PKGLEN_MAX limit") Cc: stable@vger.kernel.org Signed-off-by: Jinmo Yang <jinmo44.yang@gmail.com> Reviewed-by: Dmitry Torokhov <dmitry.torokhov@gmail.com> Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
1 parent e6f4f08 commit 6b3014e

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

drivers/hid/wacom_sys.c

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,15 +54,17 @@ static void wacom_wac_queue_insert(struct hid_device *hdev,
5454
{
5555
bool warned = false;
5656

57-
while (kfifo_avail(fifo) < size) {
57+
while (kfifo_avail(fifo) < size && !kfifo_is_empty(fifo)) {
5858
if (!warned)
5959
hid_warn(hdev, "%s: kfifo has filled, starting to drop events\n", __func__);
6060
warned = true;
6161

6262
kfifo_skip(fifo);
6363
}
6464

65-
kfifo_in(fifo, raw_data, size);
65+
if (!kfifo_in(fifo, raw_data, size))
66+
hid_warn_ratelimited(hdev, "%s: report is too large (%d)\n",
67+
__func__, size);
6668
}
6769

6870
static void wacom_wac_queue_flush(struct hid_device *hdev,

0 commit comments

Comments
 (0)