mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Muhammad Bilal <meatuni001@gmail.com>
To: dmitry.torokhov@gmail.com
Cc: jayakumar.lkml@gmail.com, linux-input@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	Muhammad Bilal <meatuni001@gmail.com>
Subject: [PATCH] Input: wacom_w8001 - validate index before storing data byte
Date: Sun, 20 Sep 2026 00:21:53 +0500	[thread overview]
Message-ID: <20260919192152.271808-2-meatuni001@gmail.com> (raw)

w8001_interrupt() stores every incoming byte at w8001->data[w8001->idx]
before the following switch on w8001->idx++ has a chance to detect an
invalid packet and reset idx. The switch only resets idx for the
specific packet lengths it recognizes; once idx has advanced past all
of those (W8001_PKTLEN_TOUCH2FG - 1 at most), any further byte falls
into default, where idx is only reset for pen-only devices without a
touch_dev (the ThinkPad X60 workaround). A touch-capable device fed a
malformed or overlong packet therefore has nothing to stop idx from
growing without bound, and w8001->data[w8001->idx] = data runs past
the end of the W8001_MAX_LENGTH-sized array.

Reset idx before it is used as an index whenever it has reached the
end of the buffer, independent of device type, so the array store is
always in range and the existing lead-byte resync in case 0 can take
over on the next byte.

Fixes: 3eb1aa43ef5c ("Input: add support for Wacom W8001 penabled serial touchscreen")
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
 drivers/input/touchscreen/wacom_w8001.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/input/touchscreen/wacom_w8001.c b/drivers/input/touchscreen/wacom_w8001.c
index d8d1cdc3f09e..bbbe7bc69776 100644
--- a/drivers/input/touchscreen/wacom_w8001.c
+++ b/drivers/input/touchscreen/wacom_w8001.c
@@ -285,6 +285,14 @@ static irqreturn_t w8001_interrupt(struct serio *serio,
 	struct w8001_coord coord;
 	unsigned char tmp;
 
+	/*
+	 * Resync if a malformed or overlong packet has pushed idx past
+	 * the end of the data array, so the array store below is always
+	 * in bounds.
+	 */
+	if (w8001->idx >= W8001_MAX_LENGTH)
+		w8001->idx = 0;
+
 	w8001->data[w8001->idx] = data;
 	switch (w8001->idx++) {
 	case 0:
-- 
2.55.0


             reply	other threads:[~2026-09-19 19:22 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19 19:21 Muhammad Bilal [this message]
2026-09-20  4:02 ` Dmitry Torokhov
2026-09-20 12:51   ` Muhammad Bilal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260919192152.271808-2-meatuni001@gmail.com \
    --to=meatuni001@gmail.com \
    --cc=dmitry.torokhov@gmail.com \
    --cc=jayakumar.lkml@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®