[PATCH 3/5] HID: wacom: check the input device in wacom_intuos_pad()
From: Jinmo Yang
Date: Sun Sep 27 2026 - 00:12:16 EST
wacom_intuos_pad() takes wacom->pad_input without checking it. An
interface that declares no pad leaves the pointer NULL on a fully
successful probe, and wacom_intuos_irq() still calls this function for
pad report ids.
Reproduced on linux-next 20260925 (x86_64, KASAN) with vendor 0x056a
product 0x032A and report id 12:
BUG: KASAN: null-ptr-deref in input_event+0x44/0xb0
Read of size 8 at addr 0000000000000028
wacom_intuos_irq+0x1b46/0x3300
wacom_wac_irq+0x1b59/0xb3f0
wacom_raw_event+0x68f/0xb60
__hid_input_report+0x398/0x4d0
uhid_char_write+0xa99/0xfc0
The function only ever serves pad reports, so the check goes at entry.
Fixes: 10059cdc0ad0 ("Input: wacom - split out the pad device for Intuos/Cintiq")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jinmo Yang <jinmo44.yang@xxxxxxxxx>
---
drivers/hid/wacom_wac.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/hid/wacom_wac.c b/drivers/hid/wacom_wac.c
index 794c2865064a..48a58a6672c2 100644
--- a/drivers/hid/wacom_wac.c
+++ b/drivers/hid/wacom_wac.c
@@ -553,6 +553,9 @@ static int wacom_intuos_pad(struct wacom_wac *wacom)
bool wrench = false, keyboard = false, mute_touch = false, menu = false,
info = false;
+ if (!input)
+ return 0;
+
/* pad packets. Works as a second tool and is always in prox */
if (!(data[0] == WACOM_REPORT_INTUOSPAD || data[0] == WACOM_REPORT_INTUOS5PAD ||
data[0] == WACOM_REPORT_CINTIQPAD))
--
2.53.0