Re: Re: [PATCH v2] HID: intel-ish-hid: clamp HID device count to MAX_HID_DEVICES
From: grayhat@xxxxxxxxxxx
Date: Thu Jul 30 2026 - 21:46:55 EST
Thanks, +Lixu noted.
Corrected tag block:
This patch was drafted with AI assistance.
Fixes: 0b28cb4bcb17 ("HID: intel-ish-hid: ISH HID client driver")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Shen Yongchao <grayhat@xxxxxxxxxxx>
Assisted-by: Hermes:kimi-k3
Let me know if you want it resent as a proper [PATCH v2].
Thanks,
Shen Yongchao
>+Lixu
>
>On Thu, 2026-07-30 at 20:25 +0800, Shen Yongchao wrote:
>> The HOSTIF_DM_ENUM_DEVICES response handler takes the HID device
>> count from the first payload byte of the ISH firmware response
>> (max 255) and stores it in hid_dev_count without any bounds
>> check. This value propagates to num_hid_devices and is used to
>> index five fixed-size arrays in struct ishtp_cl_data
>> (MAX_HID_DEVICES = 32): report_descr[], report_descr_size[],
>> hid_sensor_hubs[], hid_descr[], and hid_descr_size[].
>>
>> If the firmware reports more than 32 devices, hid_ishtp_cl_init()
>> writes past all five arrays, corrupting subsequent struct fields
>> (including work_struct members with embedded function pointers)
>> and potentially adjacent heap objects.
>>
>> Clamp hid_dev_count to MAX_HID_DEVICES at the single point where
>> it enters the driver (process_recv, ENUM_DEVICES branch), which
>> covers both the probe and the reset paths.
>>
>> This is a data-validation hardening fix: the ISH firmware is
>> within the platform trust boundary (loaded via CSME).
>>
>> This patch was drafted with AI assistance; the vulnerability
>> analysis and source-level verification were done manually.
>>
>> Signed-off-by: Shen Yongchao <grayhat@xxxxxxxxxxx>
>> Fixes: 0b28cb4bcb17 ("HID: intel-ish-hid: ISH HID client driver")
>> Cc: stable@xxxxxxxxxxxxxxx
>
>Missing
>
>Assisted-by: AGENT_NAME:MODEL_VERSION [TOOL1] [TOOL2]
>
>
>Thanks,
>Srinivas
>
>> ---
>> drivers/hid/intel-ish-hid/ishtp-hid-client.c | 2 ++
>> 1 file changed, 2 insertions(+)
>>
>> diff --git a/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> b/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> index 6d64008..XXXXXXX 100644
>> --- a/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> +++ b/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> @@ -123,6 +123,8 @@ static void process_recv(struct ishtp_cl
>> *hid_ishtp_cl, void *recv_buf,
>> break;
>> }
>> client_data->hid_dev_count = (unsigned
>> int)*payload;
>> + if (client_data->hid_dev_count >
>> MAX_HID_DEVICES)
>> + client_data->hid_dev_count =
>> MAX_HID_DEVICES;
>> if (!client_data->hid_devices)
>> client_data->hid_devices =
>> devm_kcalloc(
>> cl_data_to_dev(clien
>> t_data),