mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "David Rheinsberg" <david@readahead.eu>
To: "Peter Hutterer" <peter.hutterer@who-t.net>,
	"Jiri Kosina" <jikos@kernel.org>,
	"Benjamin Tissoires" <bentiss@kernel.org>,
	"Dmitry Torokhov" <dmitry.torokhov@gmail.com>
Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] Input: uinput/uhid - disallow control characters in phys paths
Date: Fri, 24 Jul 2026 09:51:21 +0200	[thread overview]
Message-ID: <1ed3a0b5-db39-4a82-b549-0ed7e2cf89c2@app.fastmail.com> (raw)
In-Reply-To: <20260717-wip-uinput-sanitize-phys-v1-1-f6459542ce4b@who-t.net>

Hi Peter!

On Fri, Jul 17, 2026, at 6:49 AM, Peter Hutterer wrote:
> There is no good reason to support those, no physical device will ever
> produce those. Allowing \n in phys previously triggered CVE-2026-50292
> in libinput - there the PHYS udev property value was used as part of
> another udev property value. The linebreak then caused the property
> to be split across two lines, allowing uinput devices to inject
> malicious properties. While the bug is squarely inlibinput's court
> there still isn't a good reason for control characters in uinput/uhid.
>
> Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
> ---
>  drivers/hid/uhid.c          |  1 +
>  drivers/input/misc/uinput.c |  1 +
>  include/linux/input.h       | 15 +++++++++++++++
>  3 files changed, 17 insertions(+)
>
> diff --git a/drivers/hid/uhid.c b/drivers/hid/uhid.c
> index 37b60c3aaf66..baf1fe8290f7 100644
> --- a/drivers/hid/uhid.c
> +++ b/drivers/hid/uhid.c
> @@ -513,16 +513,17 @@ static int uhid_dev_create2(struct uhid_device *uhid,
>  		ret = PTR_ERR(hid);
>  		goto err_free;
>  	}
> 
>  	BUILD_BUG_ON(sizeof(hid->name) != sizeof(ev->u.create2.name));
>  	strscpy(hid->name, ev->u.create2.name, sizeof(hid->name));
>  	BUILD_BUG_ON(sizeof(hid->phys) != sizeof(ev->u.create2.phys));
>  	strscpy(hid->phys, ev->u.create2.phys, sizeof(hid->phys));
> +	input_sanitize_phys(hid->phys);
>  	BUILD_BUG_ON(sizeof(hid->uniq) != sizeof(ev->u.create2.uniq));
>  	strscpy(hid->uniq, ev->u.create2.uniq, sizeof(hid->uniq));
> 
>  	hid->ll_driver = &uhid_hid_driver;
>  	hid->bus = ev->u.create2.bus;
>  	hid->vendor = ev->u.create2.vendor;
>  	hid->product = ev->u.create2.product;
>  	hid->version = ev->u.create2.version;
> diff --git a/drivers/input/misc/uinput.c b/drivers/input/misc/uinput.c
> index d32fa4b508fc..70fe4f3e73bf 100644
> --- a/drivers/input/misc/uinput.c
> +++ b/drivers/input/misc/uinput.c
> @@ -998,16 +998,17 @@ static long uinput_ioctl_handler(struct file 
> *file, unsigned int cmd,
> 
>  		phys = strndup_user(p, 1024);
>  		if (IS_ERR(phys)) {
>  			retval = PTR_ERR(phys);
>  			goto out;
>  		}
> 
>  		kfree(udev->dev->phys);
> +		input_sanitize_phys(phys);
>  		udev->dev->phys = phys;
>  		goto out;
> 
>  	case UI_BEGIN_FF_UPLOAD:
>  		retval = uinput_ff_upload_from_user(p, &ff_up);
>  		if (retval)
>  			goto out;
> 
> diff --git a/include/linux/input.h b/include/linux/input.h
> index 76f7aa226202..6c182f5c783f 100644
> --- a/include/linux/input.h
> +++ b/include/linux/input.h
> @@ -527,16 +527,31 @@ int input_set_keycode(struct input_dev *dev,
> 
>  bool input_match_device_id(const struct input_dev *dev,
>  			   const struct input_device_id *id);
> 
>  void input_enable_softrepeat(struct input_dev *dev, int delay, int period);
> 
>  bool input_device_enabled(struct input_dev *dev);
> 
> +/**
> + * input_sanitize_phys - replace invalid characters in a phys string
> + * @phys: the phys path to sanitize (modified in place)
> + *
> + * Replaces any control characters and non-ASCII characters with '?'.
> + **/
> +static inline void input_sanitize_phys(char *phys)
> +{
> +	char *p;
> +
> +	for (p = phys; *p; p++)
> +		if (*p < 0x20 || *p > 0x7e)
> +			*p = '?';
> +}
> +

Reviewed-by: David Rheinsberg <david@readahead.eu>

I would also be fine to just reject them in uinput, but I guess this is the less intrusive option.

Thanks a lot!
David

>  extern const struct class input_class;
> 
>  /**
>   * struct ff_device - force-feedback part of an input device
>   * @upload: Called to upload an new effect into device
>   * @erase: Called to erase an effect from device
>   * @playback: Called to request device to start playing specified effect
>   * @set_gain: Called to set specified gain
>
> ---
> base-commit: 58717b2a1365d06c8c64b72aa948541b53fe31eb
> change-id: 20260717-wip-uinput-sanitize-phys-abb6cf40e577
>
> Best regards,
> -- 
> Peter Hutterer <peter.hutterer@who-t.net>

  reply	other threads:[~2026-07-24  7:51 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-17  4:49 Peter Hutterer
2026-07-24  7:51 ` David Rheinsberg [this message]
2026-08-03 19:58   ` Jiri Kosina
2026-08-04  1:47     ` Dmitry Torokhov
2026-08-04  6:15       ` Peter Hutterer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1ed3a0b5-db39-4a82-b549-0ed7e2cf89c2@app.fastmail.com \
    --to=david@readahead.eu \
    --cc=bentiss@kernel.org \
    --cc=dmitry.torokhov@gmail.com \
    --cc=jikos@kernel.org \
    --cc=linux-input@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=peter.hutterer@who-t.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®