[PATCH 06/10] HID: mcp2200: validate READ_ALL response length

From: Jiale Yao

Date: Thu Sep 24 2026 - 10:24:16 EST


The HID core invokes raw_event callbacks before validating the report
length. mcp2200_raw_event() casts a READ_ALL response to struct
mcp_read_all_resp and reads fields through offset ten without checking that
the response contains the structure.

A one-byte READ_ALL response reproduced the issue under KASAN:

BUG: KASAN: slab-out-of-bounds in mcp2200_raw_event+0x24b/0x3a0
Read of size 1 by task hidtrigger/89
Call Trace:
mcp2200_raw_event+0x24b/0x3a0
kasan_report+0x139/0x170

Reject an incomplete READ_ALL response with a protocol error before reading
its fields. The common completion path then wakes the command waiter with
the error instead of leaving it to time out.

Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw_event length validation to hid-asus.

Fixes: 740329d7120f ("HID: mcp2200: added driver for GPIOs of MCP2200")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/hid/hid-mcp2200.c | 5 +++++
1 file changed, 5 insertions(+)

diff --git a/drivers/hid/hid-mcp2200.c b/drivers/hid/hid-mcp2200.c
index dafdd5b4a079..c6fd5fb5d578 100644
--- a/drivers/hid/hid-mcp2200.c
+++ b/drivers/hid/hid-mcp2200.c
@@ -301,6 +301,11 @@ static int mcp2200_raw_event(struct hid_device *hdev, struct hid_report *report,

switch (data[0]) {
case READ_ALL:
+ if (size < sizeof(*all_resp)) {
+ mcp->status = -EPROTO;
+ break;
+ }
+
all_resp = (struct mcp_read_all_resp *) data;
mcp->status = 0;
mcp->gpio_inval = all_resp->io_port_val_bmap;
--
2.34.1