[PATCH 04/10] HID: elo: reject short touchscreen reports

From: Jiale Yao

Date: Thu Sep 24 2026 - 10:22:46 EST


The HID core invokes raw_event callbacks before validating the report
length. elo_raw_event() only checks the first-byte packet marker before
elo_process_data() reads coordinates, flags, and pressure through offset
seven. A truncated packet beginning with the expected marker can therefore
cause an out-of-bounds read.

Require the complete eight-byte SmartSet packet before parsing it.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: d23efc19478a ("HID: add driver for ELO 4000/4500")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/hid/hid-elo.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/drivers/hid/hid-elo.c b/drivers/hid/hid-elo.c
index b8f5f3eb53a4..86e8729e1975 100644
--- a/drivers/hid/hid-elo.c
+++ b/drivers/hid/hid-elo.c
@@ -85,6 +85,9 @@ static int elo_raw_event(struct hid_device *hdev, struct hid_report *report,
if (!(hdev->claimed & HID_CLAIMED_INPUT) || list_empty(&hdev->inputs))
return 0;

+ if (size < ELO_SMARTSET_PACKET_SIZE)
+ return 0;
+
hidinput = list_first_entry(&hdev->inputs, struct hid_input, list);

switch (report->id) {
--
2.34.1