[PATCH v2] HID: magicmouse: fix null pointer dereference in magicmouse_event()
From: Nehuen Lian Bova
Date: Sat Oct 03 2026 - 03:30:28 EST
Add a guard clause to check if 'msc' and 'msc->input' is NULL
before attempting to access its fields, preventing a general
protection fault.
Fixes: b8d56ef91cc3 ("HID: magicmouse: Apple Magic Mouse 2 USB-C support")
Reported-by: syzbot+5ad4fc9c8360b68e353f@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=5ad4fc9c8360b68e353f
Signed-off-by: Nehuen Lian Bova <nehuenlian.kernel@xxxxxxxxx>
---
Changes in v2:
- Also check msc->input before dereferencing it, not just msc
drivers/hid/hid-magicmouse.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/hid/hid-magicmouse.c b/drivers/hid/hid-magicmouse.c
index d637c0477379..e6d4d4930526 100644
--- a/drivers/hid/hid-magicmouse.c
+++ b/drivers/hid/hid-magicmouse.c
@@ -553,6 +553,10 @@ static int magicmouse_event(struct hid_device *hdev, struct hid_field *field,
struct hid_usage *usage, __s32 value)
{
struct magicmouse_sc *msc = hid_get_drvdata(hdev);
+
+ if (!msc || !msc->input)
+ return 0;
+
if ((msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2 ||
msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2_USBC) &&
field->report->id == MOUSE2_REPORT_ID) {
--
2.43.0