* [PATCH] HID: magicmouse: fix null pointer dereference in magicmouse_event()
@ 2026-10-03 1:18 Nehuen Lian Bova
2026-10-03 7:29 ` [PATCH v2] " Nehuen Lian Bova
0 siblings, 1 reply; 2+ messages in thread
From: Nehuen Lian Bova @ 2026-10-03 1:18 UTC (permalink / raw)
To: jikos, bentiss
Cc: linux-input, linux-kernel, Nehuen Lian Bova, syzbot+5ad4fc9c8360b68e353f
Add a guard clause to check if 'msc' is NULL before attempting
to access its fields, preventing a general protection fault.
Fixes: b8d56ef91cc3 ("HID: magicmouse: Apple Magic Mouse 2 USB-C support")
Reported-by: syzbot+5ad4fc9c8360b68e353f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5ad4fc9c8360b68e353f
Signed-off-by: Nehuen Lian Bova <nehuenlian.kernel@gmail.com>
---
drivers/hid/hid-magicmouse.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/hid/hid-magicmouse.c b/drivers/hid/hid-magicmouse.c
index d637c0477379..85454250355f 100644
--- a/drivers/hid/hid-magicmouse.c
+++ b/drivers/hid/hid-magicmouse.c
@@ -553,6 +553,10 @@ static int magicmouse_event(struct hid_device *hdev, struct hid_field *field,
struct hid_usage *usage, __s32 value)
{
struct magicmouse_sc *msc = hid_get_drvdata(hdev);
+
+ if (!msc)
+ return 0;
+
if ((msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2 ||
msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2_USBC) &&
field->report->id == MOUSE2_REPORT_ID) {
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH v2] HID: magicmouse: fix null pointer dereference in magicmouse_event()
2026-10-03 1:18 [PATCH] HID: magicmouse: fix null pointer dereference in magicmouse_event() Nehuen Lian Bova
@ 2026-10-03 7:29 ` Nehuen Lian Bova
0 siblings, 0 replies; 2+ messages in thread
From: Nehuen Lian Bova @ 2026-10-03 7:29 UTC (permalink / raw)
To: Jiri Kosina, Benjamin Tissoires, linux-input
Cc: Aditya Garg, linux-kernel, Nehuen Lian Bova, syzbot+5ad4fc9c8360b68e353f
Add a guard clause to check if 'msc' and 'msc->input' is NULL
before attempting to access its fields, preventing a general
protection fault.
Fixes: b8d56ef91cc3 ("HID: magicmouse: Apple Magic Mouse 2 USB-C support")
Reported-by: syzbot+5ad4fc9c8360b68e353f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5ad4fc9c8360b68e353f
Signed-off-by: Nehuen Lian Bova <nehuenlian.kernel@gmail.com>
---
Changes in v2:
- Also check msc->input before dereferencing it, not just msc
drivers/hid/hid-magicmouse.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/hid/hid-magicmouse.c b/drivers/hid/hid-magicmouse.c
index d637c0477379..e6d4d4930526 100644
--- a/drivers/hid/hid-magicmouse.c
+++ b/drivers/hid/hid-magicmouse.c
@@ -553,6 +553,10 @@ static int magicmouse_event(struct hid_device *hdev, struct hid_field *field,
struct hid_usage *usage, __s32 value)
{
struct magicmouse_sc *msc = hid_get_drvdata(hdev);
+
+ if (!msc || !msc->input)
+ return 0;
+
if ((msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2 ||
msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2_USBC) &&
field->report->id == MOUSE2_REPORT_ID) {
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-03 7:30 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 1:18 [PATCH] HID: magicmouse: fix null pointer dereference in magicmouse_event() Nehuen Lian Bova
2026-10-03 7:29 ` [PATCH v2] " Nehuen Lian Bova
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®