Re: [PATCH] HID: bpf: reject oversized device events before copying

From: bot+bpf-ci

Date: Mon Sep 14 2026 - 21:03:34 EST


> HID-BPF allocates its device-event buffer from the largest report in the
> device's parsed report descriptor. dispatch_hid_bpf_device_event() then
> copies the transport-provided report into that buffer before checking its
> size.
>
> An input report larger than the allocated event buffer therefore causes
> a heap out-of-bounds write when a device-event program is attached. The
> later check of the BPF program's return value cannot prevent the initial
> copy.
>
> Reject reports that exceed either the transport buffer or the persistent
> HID-BPF event buffer before clearing or copying the data.
>
> With a 64-byte event allocation, a same-file KUnit test produced a
> one-byte KASAN out-of-bounds write for a 65-byte report in three runs.
> The 64-byte boundary remained clean. After this change, both cases were
> clean in three runs and the oversized report returned -EINVAL. The test
> exercised the production dispatch function but not the complete UHID and
> BPF attachment path.

This isn't a bug, but could the last paragraph be trimmed to one
sentence naming the reproducer, since the KUnit test it refers to is not
part of the patch? The rest of the message clearly states the problem
and the fix, and this final paragraph reads more like a test report than
a changelog - it counts test runs and caveats its own coverage.


---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md

CI run summary: https://github.com/kernel-patches/bpf/actions/runs/34914058900