From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f179.google.com (mail-pl1-f179.google.com [209.85.214.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8C32C2C86D for ; Thu, 23 Jul 2026 03:28:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.179 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784777301; cv=none; b=kk+VUXXsop1z/GEBjlviimRZVLk8oqp4SWCv+YfO83+CQ6NGBXHvs94wmjJfIdzmWpgC6B0NZhCeAUymrp/yYcZ5atNKkNW0XRv0mhcw2VfqtrImVUknyLPnmX9CjFKv74YuQ2H+Esy+To9Q6+gmdsGxb5WWUfD0PpNm9JCch/Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784777301; c=relaxed/simple; bh=r8iYdQWHa9VJS775/4n6zn3PGSHvLkZImtets05yhb8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=h2v27LVwZkUfE60wz7vKdv9Kuek6QDhGW6THqEAqIhGulLR2gvQUq1TL+sRn4GBS/0leVhidQZmwD1YMWJNVD/HXnISOrZdxm6tuFoRi7iknTC5PgqpuHAchOgaqlgFebeCTQ3EDnJTR+ZWXJLlMDkJzNiQwDTay7cVO9l2uJ48= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qF3cM83L; arc=none smtp.client-ip=209.85.214.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qF3cM83L" Received: by mail-pl1-f179.google.com with SMTP id d9443c01a7336-2cc97653887so2095815ad.1 for ; Wed, 22 Jul 2026 20:28:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784777296; x=1785382096; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=t/Igs/v4fkYLbH3ZnRzuIP4kc2pMGS9giRIUagxHqkY=; b=qF3cM83L8CqP/yOI7qRqfqmo6O0zVq2lGzy7tOur1sARKXfJ8yMq7pjepgir8OpGvR YvPDg+kdLnOAcFK+LpJ1woxDcbRB2jNdCTEs6N0mfJYf4coPIfqOo1GJbAYqQ+08i45V dvuXohs7IxLXgkrnhEvwAuieUc3yAf4qECUuXgBDNXkiZ2YbAawWCfbk9aTXLMTbMHGr zDrL092p0SI4UdJONd8sXaB38XBEcNuYG6QGfC9aFpydXmC1hFt/Ec521C0Z1HWSWAnK k/KkpXBn2VPDUfaxymXJmWP4IgTAUumbVLsAaOH5Y6IV6kLhB13BQtfZSoETVkaGH6/o UR3Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784777296; x=1785382096; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=t/Igs/v4fkYLbH3ZnRzuIP4kc2pMGS9giRIUagxHqkY=; b=RG/0CZedPGMb5zrI5UAsYstMmMvvP8Ix57UvRLpOULqD4RIlxJAFPGfvEQ+7X5zLww WZ5t6ox/8/R3KYb7nOHfZf6h92H/s+Q0UqWXMFnCHEeTeP/x8FdkYtVAgBVjK5mEjvcV tH+L8DP0DbgBZIvOeHOCSwY4LWpVBo7ZnQu3XQeCoPVplVaTQ78tWqvgFBmzr1TgGNJq Q11kOMJAE6+8/6UoanzEBot/iiuq8CCF8ybGZnhDU/BSMtl/l2oPIFEtQ226K/4fqq2C z2J2PGg5XYA4fJJdYfDfjvP4i0ojXp8RJ8jIND+3BUjKEdAZITHHqXNemeqY9jkJxghh nZxg== X-Forwarded-Encrypted: i=1; AHgh+RqAo8zrn3xzILJlSrszBPiIlGKb2FWlT/R88q0r+uHcoU5BOptLxLY1jsLfm632EDaHGqG9rehkdYOXjFw=@vger.kernel.org X-Gm-Message-State: AOJu0YxK5dxmMoOFjzYJFFwQmJHPK02e+0RK1rS8l4JtTOeRZ3mylrnm rrSeKRkJ5SWeWPYWtEsgeYB6wMipXdR0z1CuLzp/R8+t3Z8M21bPeBVO X-Gm-Gg: AR+sD12URVLS6JLhBNQmKhu/u54eMjW22GiK6MxjGhzz/eHosfWhFYIF6VXla4oxm2u ff/iJDcWje7SHqaeiQsn98taUc0R1lYX5l2B+tMSrAZ579DTdxvy26tREr448N49FINJzMKG9iR Ohilpk8WZ7EIqdPU2D2McpvDv6OUsNYDroFS5zoJzM6wswiiqPBMgRH2AiMTa5Qah+LmGnXJuRl iGI2j48DozIw+ZpXi4ScoOSzzhhAJOc2jWAoHW0jeyIDzzEjLv7TyHErka7rA0uvZtNAQ+Rp9Uc pxOG1DX6nevKKesp2fOzUpPouFN2LvOT9T8GZBXvBNpVTQsyfpNV+3EW0otJiptbLcG26T7h8Ze rzk8Zig/lSorY94936wOjuMxjHQgzapbNUYfX3KmpHutWQIYVf7N1odpz7SyGTDOQo2OJ0kchI0 m669uUQtZUTg5593B6ROD1EYz3FWUr8L7gFXq1hqLGEAz5NJzxRxto X-Received: by 2002:a17:903:3c70:b0:2cc:fe03:dc75 with SMTP id d9443c01a7336-2cfa748cd86mr17871995ad.27.1784777295936; Wed, 22 Jul 2026 20:28:15 -0700 (PDT) Received: from DESKTOP-L3Q0GIV.localdomain ([203.230.195.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd7157sm24538485ad.18.2026.07.22.20.28.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 20:28:15 -0700 (PDT) From: Sangho Lee To: luiz.dentz@gmail.com, marcel@holtmann.org, linux-bluetooth@vger.kernel.org Cc: jikos@kernel.org, alan@signal11.us, padovan@profusion.mobi, linux-kernel@vger.kernel.org, stable@vger.kernel.org, kudo3228@gmail.com Subject: [PATCH 2/2] Bluetooth: HIDP: validate numbered report payloads Date: Thu, 23 Jul 2026 12:28:07 +0900 Message-ID: <20260723032807.1616487-3-kudo3228@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723032807.1616487-1-kudo3228@gmail.com> References: <20260723032807.1616487-1-kudo3228@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]. A connected HIDP peer can reply with only a DATA transaction header, leaving the skb empty after the header is removed. KMSAN reports an uninitialized-value use in hidp_session_run(), with the value originating in __alloc_skb() through vhci_write(). The transaction header checks remove the empty-frame reports, but this report remains until the payload check is added. The comparison can also consume a peer-controlled byte beyond the declared L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made the current code accept that byte as report ID 1 and complete HIDIOCGFEATURE with a zero-byte result. With this change the malformed response is rejected with -EIO, while a subsequent valid response still succeeds. Require a payload byte before comparing a numbered report ID. Unnumbered reports continue to accept an empty payload. Fixes: 0ff1731a1ae5 ("HID: bt: Add support for hidraw HIDIOCGFEATURE and HIDIOCSFEATURE") Cc: stable@vger.kernel.org Signed-off-by: Sangho Lee --- net/bluetooth/hidp/core.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/net/bluetooth/hidp/core.c b/net/bluetooth/hidp/core.c index 194208d03d18..f5bdf9f1ca63 100644 --- a/net/bluetooth/hidp/core.c +++ b/net/bluetooth/hidp/core.c @@ -543,9 +543,10 @@ static int hidp_process_data(struct hidp_session *session, struct sk_buff *skb, } if (test_bit(HIDP_WAITING_FOR_RETURN, &session->flags) && - param == session->waiting_report_type) { + param == session->waiting_report_type) { if (session->waiting_report_number < 0 || - session->waiting_report_number == skb->data[0]) { + (skb->len && + session->waiting_report_number == skb->data[0])) { /* hidp_get_raw_report() is waiting on this report. */ session->report_return = skb; done_with_skb = 0; -- 2.43.0