Re: [PATCH v2] Input: iforce - validate input packet lengths

From: Dmitry Torokhov

Date: Fri Jul 24 2026 - 23:56:53 EST


On Mon, Jul 20, 2026 at 07:50:18PM +0800, Pengpeng Hou wrote:
> iforce_process_packet() reads fixed fields from joystick, wheel and status
> packets without first checking their lengths. In particular, the shared
> hats-and-buttons helper unconditionally reads data[6]. The status tail is
> a sequence of 16-bit effect addresses, but an incomplete final address is
> also consumed. A successful zero-length USB URB additionally reads the
> packet ID before the common parser is called.
>
> Reject the zero-length USB transfer, require the seven-byte joystick and
> wheel prefixes and the two-byte status prefix, and consume only complete
> status-tail addresses.
>
> Signed-off-by: Pengpeng Hou <pengpeng@xxxxxxxxxxx>

Applied, thank you.

--
Dmitry