RE: [PATCH v2] HID: intel-ish-hid: clamp HID device count to MAX_HID_DEVICES

From: Zhang, Lixu

Date: Fri Jul 31 2026 - 02:50:48 EST


>-----Original Message-----
>From: srinivas pandruvada <srinivas.pandruvada@xxxxxxxxxxxxxxx>
>Sent: Friday, July 31, 2026 2:11 AM
>To: Shen Yongchao <grayhat@xxxxxxxxxxx>; Greg Kroah-Hartman
><gregkh@xxxxxxxxxxxxxxxxxxx>; Zhang, Lixu <lixu.zhang@xxxxxxxxx>
>Cc: Jiri Kosina <jikos@xxxxxxxxxx>; Benjamin Tissoires <bentiss@xxxxxxxxxx>;
>linux-input@xxxxxxxxxxxxxxx; linux-kernel@xxxxxxxxxxxxxxx
>Subject: Re: [PATCH v2] HID: intel-ish-hid: clamp HID device count to
>MAX_HID_DEVICES
>
>+Lixu

Code-wise, the changes look good to me.

Tested-by: Zhang Lixu <lixu.zhang@xxxxxxxxx>

Thanks,
Lixu

>
>On Thu, 2026-07-30 at 20:25 +0800, Shen Yongchao wrote:
>> The HOSTIF_DM_ENUM_DEVICES response handler takes the HID device
>count
>> from the first payload byte of the ISH firmware response (max 255) and
>> stores it in hid_dev_count without any bounds check.  This value
>> propagates to num_hid_devices and is used to index five fixed-size
>> arrays in struct ishtp_cl_data (MAX_HID_DEVICES = 32): report_descr[],
>> report_descr_size[], hid_sensor_hubs[], hid_descr[], and
>> hid_descr_size[].
>>
>> If the firmware reports more than 32 devices, hid_ishtp_cl_init()
>> writes past all five arrays, corrupting subsequent struct fields
>> (including work_struct members with embedded function pointers) and
>> potentially adjacent heap objects.
>>
>> Clamp hid_dev_count to MAX_HID_DEVICES at the single point where it
>> enters the driver (process_recv, ENUM_DEVICES branch), which covers
>> both the probe and the reset paths.
>>
>> This is a data-validation hardening fix: the ISH firmware is within
>> the platform trust boundary (loaded via CSME).
>>
>> This patch was drafted with AI assistance; the vulnerability analysis
>> and source-level verification were done manually.
>>
>> Signed-off-by: Shen Yongchao <grayhat@xxxxxxxxxxx>
>> Fixes: 0b28cb4bcb17 ("HID: intel-ish-hid: ISH HID client driver")
>> Cc: stable@xxxxxxxxxxxxxxx
>
>Missing
>
>Assisted-by: AGENT_NAME:MODEL_VERSION [TOOL1] [TOOL2]
>
>
>Thanks,
>Srinivas
>