[PATCH 00/10] HID: validate short reports in raw_event callbacks
From: Jiale Yao
Date: Thu Sep 24 2026 - 10:52:30 EST
__hid_input_report() calls a driver's raw_event callback before
hid_report_raw_event() validates the received length against the report
descriptor. A raw_event callback must therefore validate size before
accessing fixed offsets or casting data to a protocol structure.
Ten HID drivers currently access fields beyond the received length when a
device supplies a truncated report. Add protocol-specific checks before
those accesses. The patches are independent and each changes one driver.
The mcp2200, pxrc, and zydacron cases were reproduced with a fake HID
transport under KASAN. Their individual commit messages include the
relevant reports. The remaining paths were verified by following their
fixed-offset accesses from raw_event.
This follows the local raw_event size check added to hid-asus by commit
47669bec44fe ("HID: asus: refactor the two workqueues and init sequence").
Jiale Yao (10):
HID: alps: reject short input reports
HID: cougar: reject short special-key reports
HID: cp2112: validate response report lengths
HID: elo: reject short touchscreen reports
HID: logitech-dj: validate unnumbered keyboard reports
HID: mcp2200: validate READ_ALL response length
HID: mcp2221: validate response report length
HID: prodikeys: validate fixed-format MIDI reports
HID: pxrc: reject short input reports
HID: zydacron: validate key report length
drivers/hid/hid-alps.c | 8 +++++++-
drivers/hid/hid-cougar.c | 3 +++
drivers/hid/hid-cp2112.c | 9 ++++++++-
drivers/hid/hid-elo.c | 3 +++
drivers/hid/hid-logitech-dj.c | 3 +++
drivers/hid/hid-mcp2200.c | 5 +++++
drivers/hid/hid-mcp2221.c | 2 +-
drivers/hid/hid-prodikeys.c | 7 ++++++-
drivers/hid/hid-pxrc.c | 3 +++
drivers/hid/hid-zydacron.c | 3 +++
10 files changed, 42 insertions(+), 4 deletions(-)
--
2.34.1