]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
HID: fix a couple of off-by-ones
authorJiri Kosina <jkosina@suse.cz>
Thu, 21 Aug 2014 14:57:48 +0000 (09:57 -0500)
committerWilly Tarreau <w@1wt.eu>
Fri, 18 Sep 2015 11:51:53 +0000 (13:51 +0200)
commit 4ab25786c87eb20857bbb715c3ae34ec8fd6a214 upstream.

There are a few very theoretical off-by-one bugs in report descriptor size
checking when performing a pre-parsing fixup. Fix those.

Reported-by: Ben Hawkes <hawkes@google.com>
Reviewed-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
[bwh: Backported to 2.6.32:
 - Adjust context
 - Drop change to a quirk in hid-lg.c that doesn't exist here]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2014-3184

Signed-off-by: Willy Tarreau <w@1wt.eu>
drivers/hid/hid-cherry.c
drivers/hid/hid-kye.c
drivers/hid/hid-lg.c
drivers/hid/hid-monterey.c
drivers/hid/hid-petalynx.c
drivers/hid/hid-sunplus.c

index 7e597d7f770fedb35284ef5a3d827cf01872559f..bfce74e2e074e7b6005e5effb59df2500b5d4170 100644 (file)
@@ -29,7 +29,7 @@
 static void ch_report_fixup(struct hid_device *hdev, __u8 *rdesc,
                unsigned int rsize)
 {
-       if (rsize >= 17 && rdesc[11] == 0x3c && rdesc[12] == 0x02) {
+       if (rsize >= 18 && rdesc[11] == 0x3c && rdesc[12] == 0x02) {
                dev_info(&hdev->dev, "fixing up Cherry Cymotion report "
                                "descriptor\n");
                rdesc[11] = rdesc[16] = 0xff;
index f8871712b7b53cbbe4e5dac5c7b651691a38c99d..30f723b7f2675789056ee6da2c5d4ff9b704de2b 100644 (file)
@@ -26,7 +26,7 @@
 static void kye_report_fixup(struct hid_device *hdev, __u8 *rdesc,
                unsigned int rsize)
 {
-       if (rsize >= 74 &&
+       if (rsize >= 75 &&
                rdesc[61] == 0x05 && rdesc[62] == 0x08 &&
                rdesc[63] == 0x19 && rdesc[64] == 0x08 &&
                rdesc[65] == 0x29 && rdesc[66] == 0x0f &&
index 0f870a3243ed1ef2a9870c4a32c63b7519975c03..6d3437413b8739e8ab7e749202090b08d61c5b29 100644 (file)
@@ -44,7 +44,7 @@ static void lg_report_fixup(struct hid_device *hdev, __u8 *rdesc,
 {
        unsigned long quirks = (unsigned long)hid_get_drvdata(hdev);
 
-       if ((quirks & LG_RDESC) && rsize >= 90 && rdesc[83] == 0x26 &&
+       if ((quirks & LG_RDESC) && rsize >= 91 && rdesc[83] == 0x26 &&
                        rdesc[84] == 0x8c && rdesc[85] == 0x02) {
                dev_info(&hdev->dev, "fixing up Logitech keyboard report "
                                "descriptor\n");
index 2cd05aa244b9cfb78739bb1c0f7c5da71f43f0ff..eaa2ac82074bca6b880bd563c78cffffcaef68aa 100644 (file)
@@ -25,7 +25,7 @@
 static void mr_report_fixup(struct hid_device *hdev, __u8 *rdesc,
                unsigned int rsize)
 {
-       if (rsize >= 30 && rdesc[29] == 0x05 && rdesc[30] == 0x09) {
+       if (rsize >= 31 && rdesc[29] == 0x05 && rdesc[30] == 0x09) {
                dev_info(&hdev->dev, "fixing up button/consumer in HID report "
                                "descriptor\n");
                rdesc[30] = 0x0c;
index 500fbd0652dc4be5354743dab0961aef43cf6989..38fa74dbfee77988e08d37d0fc3188319af3bca9 100644 (file)
@@ -26,7 +26,7 @@
 static void pl_report_fixup(struct hid_device *hdev, __u8 *rdesc,
                unsigned int rsize)
 {
-       if (rsize >= 60 && rdesc[39] == 0x2a && rdesc[40] == 0xf5 &&
+       if (rsize >= 62 && rdesc[39] == 0x2a && rdesc[40] == 0xf5 &&
                        rdesc[41] == 0x00 && rdesc[59] == 0x26 &&
                        rdesc[60] == 0xf9 && rdesc[61] == 0x00) {
                dev_info(&hdev->dev, "fixing up Petalynx Maxter Remote report "
index 438107d9f1b2a3b5d11be27c2f9e1deca5690108..ac0d4880cdd8e0534de10b5bd4db304990ff0101 100644 (file)
@@ -25,7 +25,7 @@
 static void sp_report_fixup(struct hid_device *hdev, __u8 *rdesc,
                unsigned int rsize)
 {
-       if (rsize >= 107 && rdesc[104] == 0x26 && rdesc[105] == 0x80 &&
+       if (rsize >= 112 && rdesc[104] == 0x26 && rdesc[105] == 0x80 &&
                        rdesc[106] == 0x03) {
                dev_info(&hdev->dev, "fixing up Sunplus Wireless Desktop "
                                "report descriptor\n");