[PATCH] HID: sensor-hub: reject short input reports

From: Jiale Yao

Date: Thu Sep 24 2026 - 11:15:54 EST


The HID driver raw_event callback runs before HID core validates the
received report length. sensor_hub_raw_event() walks the fields described
by the report descriptor and advances through raw_data by each field size
without checking that the received buffer contains the complete report.
A truncated report can therefore make the field copy and capture callbacks
read beyond the received data.

Reject input reports shorter than the length derived from their report
descriptor before walking any fields. Commit 47669bec44fe ("HID: asus:
refactor the two workqueues and init sequence") added equivalent raw-event
length validation to hid-asus.

Fixes: 401ca24fb34a ("HID: sensors: introduce sensor framework")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/hid/hid-sensor-hub.c | 2 ++
1 file changed, 2 insertions(+)

diff --git a/drivers/hid/hid-sensor-hub.c b/drivers/hid/hid-sensor-hub.c
index 6470a290ebfc..d3e7bdac916c 100644
--- a/drivers/hid/hid-sensor-hub.c
+++ b/drivers/hid/hid-sensor-hub.c
@@ -542,6 +542,8 @@ static int sensor_hub_raw_event(struct hid_device *hdev,
hid_dbg(hdev, "maxfield:%d\n", report->maxfield);
if (report->type != HID_INPUT_REPORT)
return 1;
+ if (size < hid_report_len(report))
+ return 1;

ptr = raw_data;
if (report->id)
--
2.34.1