]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
authorRichard Davies <richard@arachsys.com>
Mon, 3 Aug 2026 00:53:10 +0000 (17:53 -0700)
committerDmitry Torokhov <dmitry.torokhov@gmail.com>
Mon, 3 Aug 2026 01:20:24 +0000 (18:20 -0700)
Make finger2 (and also finger1) unsigned, so that if the finger index in
the packet is 0 then subtracting 1 creates an array index which overflows
above the existing check for FOC_MAX_FINGERS, as the existing comment says
it should, instead of writing to state->fingers[-1].

Fixes: 05be1d079ec0 ("Input: psmouse - support for the FocalTech PS/2 protocol extensions")
Signed-off-by: Richard Davies <richard@arachsys.com>
Link: https://patch.msgid.link/20260701190932.14960-1-richard@arachsys.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
drivers/input/mouse/focaltech.c

index 43f9939b7c63ce54f70a4e9405183d5f405ff14b..d3ad4af5aa09d72762a6a4e3970e4b6ce8e94757 100644 (file)
@@ -197,7 +197,7 @@ static void focaltech_process_rel_packet(struct psmouse *psmouse,
 {
        struct focaltech_data *priv = psmouse->private;
        struct focaltech_hw_state *state = &priv->state;
-       int finger1, finger2;
+       unsigned int finger1, finger2;
 
        state->pressed = packet[0] >> 7;
        finger1 = ((packet[0] >> 4) & 0x7) - 1;