Re: [PATCH] Input: tca8418_keypad - fix potential infinite loop and OOB, access on I2C error

From: Dmitry Torokhov

Date: Fri Jul 24 2026 - 20:47:16 EST


Hi Liang,

On Thu, Jul 23, 2026 at 11:41:43AM +0800, Liang Zhan wrote:
> From 187224ee38e19fd3f74bfc08d1908c97398fef82 Mon Sep 17 00:00:00 2001
> From: Zhian Liang <liangzhan5dev@xxxxxxxxx>
> Date: Thu, 23 Jul 2026 00:08:15 +0800
> Subject: [PATCH] Input: tca8418_keypad - fix potential infinite loop and OOB
>  access on I2C error
> MIME-Version: 1.0
> Content-Type: text/plain; charset=UTF-8
> Content-Transfer-Encoding: 8bit
> If the I2C bus returns 0xFF (e.g., due to a stuck bus or device fault),
> the original code would treat it as a valid key event, leading to two
> critical issues:
> 1. The loop in tca8418_read_keypad() would never terminate because the
>    condition "reg <= 0" is false for 0xFF (255). This stalls the threaded
>    IRQ handler indefinitely.

Not everything that Sashiko generates needs to be taken literally. If
transfer glitches I expect I2C core signal this properly.

> 2. The extracted hardware keycode (127) is used to compute row/col
>    indices that exceed the valid range (rows*cols ≤ 80), causing an
>    out-of-bounds read on "keymap[code]" when reporting the key.
> Fix both by:
> - Recognizing 0xFF as an empty FIFO condition (along with 0x00).
> - Validating the keycode before calculating row/col, skipping invalid
>   codes and preventing array overrun.
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Zhian Liang <liangzhan5dev@xxxxxxxxx>
> ---
>  drivers/input/keyboard/tca8418_keypad.c | 11 +++++++++--
>  1 file changed, 9 insertions(+), 2 deletions(-)
> diff --git a/drivers/input/keyboard/tca8418_keypad.c
> b/drivers/input/keyboard/tca8418_keypad.c
> index b124e576feca..cec6a589192d 100644
> --- a/drivers/input/keyboard/tca8418_keypad.c
> +++ b/drivers/input/keyboard/tca8418_keypad.c
> @@ -171,13 +171,20 @@ static void tca8418_read_keypad(struct tca8418_keypad
> *keypad_data)
>             break;
>         }
> -       /* Assume that key code 0 signifies empty FIFO */
> -       if (reg <= 0)
> +       /* 0x00 =  empty FIFO, 0xFF = likely bus fault */
> +       if (reg == 0 || reg == 0xFF)
>             break;
>         state = reg & KEY_EVENT_VALUE;
>         code  = reg & KEY_EVENT_CODE;

Jet's move the check for empty FIFO here:

if (!code)
return;

> +       /* validate keycode: must be non-zero and within hardware limits */
> +       if (code == 0 || code > TCA8418_MAX_ROWS * TCA8418_MAX_COLS){

This check is not sufficient if keypad is configured to use just part of
potential matrix. We need to make sure that row and col is within the
rows and cold limits we set up for the keypad.

Thanks.

--
Dmitry