]> git.ipfire.org Git - thirdparty/linux.git/commit
HID: lenovo: Fix buffer over-read and unaligned access in X12 Tab raw_event handler
authorKean <rh_king@163.com>
Thu, 14 May 2026 12:58:38 +0000 (20:58 +0800)
committerBenjamin Tissoires <bentiss@kernel.org>
Thu, 21 May 2026 15:10:27 +0000 (17:10 +0200)
commitc7ee0b73c8c4dfb7eafa49aaef5247890862a948
tree1776b87122c55e417af8147564bcc130ace29d65
parent07466fc91c55532edcfb5c6a7ccd2ea52728d6bd
HID: lenovo: Fix buffer over-read and unaligned access in X12 Tab raw_event handler

In lenovo_raw_event(), the X12 Tab keyboard handler reads a 4-byte
little-endian value from the raw HID report buffer but:

  1. The size guard is size >= 3, while the access reads 4 bytes.
     A malformed 3-byte report with ID 0x03 would over-read the
     buffer by one byte.

  2. Casting u8 *data directly to __le32 * can trigger unaligned
     access faults on architectures like ARM, MIPS, and SPARC,
     because HID input buffers carry no alignment guarantee.
     (e.g. uhid payloads start at offset 6 in struct uhid_event,
     giving only 2-byte alignment.)

Fix both by tightening the size check to >= 4 and replacing the
open-coded cast + le32_to_cpu() with get_unaligned_le32(), which
handles the LE-to-CPU conversion safely regardless of alignment.

Link: https://sashiko.dev/#/message/20260512044911.99B6DC2BCB0%40smtp.kernel.org
Assisted-by: CLAUDE:claude-4-sonnet
Signed-off-by: Kean <rh_king@163.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
drivers/hid/hid-lenovo.c