]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
authorGuenter Roeck <linux@roeck-us.net>
Wed, 8 Jul 2026 00:52:54 +0000 (17:52 -0700)
committerGuenter Roeck <linux@roeck-us.net>
Wed, 8 Jul 2026 03:02:56 +0000 (20:02 -0700)
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.

Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().

Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 40c3a44542257 ("hwmon: add Corsair Commander Pro driver")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
drivers/hwmon/corsair-cpro.c

index b6e508e43fa17f8c2d3b9360f4294f6d282c0d1b..8354a002f4c5e13223826f6bf7924e249899870f 100644 (file)
@@ -645,6 +645,7 @@ static int ccp_probe(struct hid_device *hdev, const struct hid_device_id *id)
 
 out_hw_close:
        hid_hw_close(hdev);
+       hid_device_io_stop(hdev);
 out_hw_stop:
        hid_hw_stop(hdev);
        return ret;