[RFC PATCH] Input: goodix-berlin - validate the complete IC info misc block

From: Zhang Jiaxi

Date: Thu Oct 08 2026 - 18:36:57 EST


From: Jiaxi Zhang <z1529105815@xxxxxxxxxxx>

The variable-length parameter arrays are checked while advancing the
offset, but the final misc structure is dereferenced without checking that
the complete structure fits in the reported IC info length. Reject a
truncated misc block before reading its register addresses.

Extracted from the v165 source; no firmware-mode change is included.

Signed-off-by: Jiaxi Zhang <z1529105815@xxxxxxxxxxx>

---
The bounds payload is unchanged and reuses its successful exact-target
object compilation. No coordinate-mode or reset/resume change is included.

diff --git a/drivers/input/touchscreen/goodix_berlin_core.c b/drivers/input/touchscreen/goodix_berlin_core.c
--- a/drivers/input/touchscreen/goodix_berlin_core.c
+++ b/drivers/input/touchscreen/goodix_berlin_core.c
@@ -347,6 +347,9 @@
ADVANCE_LE16_PARAMS(); /* stylus_freq_num */
#undef ADVANCE_LE16_PARAMS

+ if (offset + sizeof(*misc) > length)
+ goto invalid_offset;
+
misc = (struct goodix_berlin_ic_info_misc *)&data[offset];
cd->touch_data_addr = le32_to_cpu(misc->touch_data_addr);