[PATCH v5 3/5] hwmon: (aquacomputer_d5next) Validate incoming status reports
From: Vas Zayarskiy
Date: Sun Sep 27 2026 - 15:14:12 EST
The raw-event callback runs before HID core pads a short report. Check
that the report is an input report and that its length matches the HID
report descriptor before decoding sensor fields. Otherwise a truncated
report can be read past its received data, and a feature report with the
same ID can be mistaken for sensor data.
Apply these checks to every device using the shared raw-event path and
check the report ID byte before updating the cache. Legacy devices keep
using their separate feature-report read path.
Assisted-by: LLM sparse
Signed-off-by: Vas Zayarskiy <contact@xxxxxxxxx>
---
drivers/hwmon/aquacomputer_d5next.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/hwmon/aquacomputer_d5next.c b/drivers/hwmon/aquacomputer_d5next.c
index 0bd1886ef..f80027b27 100644
--- a/drivers/hwmon/aquacomputer_d5next.c
+++ b/drivers/hwmon/aquacomputer_d5next.c
@@ -1334,7 +1334,8 @@ static int aqc_raw_event(struct hid_device *hdev, struct hid_report *report, u8
int i, j, sensor_value;
struct aqc_data *priv;
- if (report->id != STATUS_REPORT_ID)
+ if (report->id != STATUS_REPORT_ID || report->type != HID_INPUT_REPORT ||
+ size != hid_report_len(report) || data[0] != STATUS_REPORT_ID)
return 0;
priv = hid_get_drvdata(hdev);