summaryrefslogtreecommitdiff
path: root/drivers/hid/hid-steam.c
diff options
context:
space:
mode:
authorVicki Pfau <vi@endrift.com>2026-07-29 21:12:33 -0700
committerJiri Kosina <jkosina@suse.com>2026-08-03 21:00:27 +0200
commit33ff7b49c38b39b1f3d27db508ac0720fb25c08a (patch)
treedae468a3235e6ad045bfef2e0c98f930fe3dfe43 /drivers/hid/hid-steam.c
parent9f8ee99f831b2711624ef81d0abba1d183f28b09 (diff)
downloadlinux-next-33ff7b49c38b39b1f3d27db508ac0720fb25c08a.tar.gz
linux-next-33ff7b49c38b39b1f3d27db508ac0720fb25c08a.zip
HID: steam: Reject short reads
Steam Controller FEATURE reports encode the size of the message in the message itself. Previously we were trusting that the size reported matched the size we actually read, leading to a potential issue with short reads. Instead, we should actually verify the length of the read. Fixes: c164d6abf384 ("HID: add driver for Valve Steam Controller") Reported-by: syzbot+75f3f9bff8c510602d36@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=75f3f9bff8c510602d36 Signed-off-by: Vicki Pfau <vi@endrift.com> Link: https://syzkaller.appspot.com/bug?extid=75f3f9bff8c510602d36 Signed-off-by: Jiri Kosina <jkosina@suse.com>
Diffstat (limited to 'drivers/hid/hid-steam.c')
-rw-r--r--drivers/hid/hid-steam.c29
1 files changed, 25 insertions, 4 deletions
diff --git a/drivers/hid/hid-steam.c b/drivers/hid/hid-steam.c
index ddd439dd069b..3b4a588c20ad 100644
--- a/drivers/hid/hid-steam.c
+++ b/drivers/hid/hid-steam.c
@@ -357,6 +357,13 @@ static int steam_recv_report(struct steam_device *steam,
u8 *buf;
int ret;
+ /*
+ * All reports start with a two byte header.
+ * We must read at least two bytes to get a sensible output.
+ */
+ if (size < 2)
+ return -EINVAL;
+
r = steam->hdev->report_enum[HID_FEATURE_REPORT].report_id_hash[0];
if (!r) {
hid_err(steam->hdev, "No HID_FEATURE_REPORT submitted - nothing to read\n");
@@ -380,16 +387,30 @@ static int steam_recv_report(struct steam_device *steam,
buf, hid_report_len(r) + 1,
HID_FEATURE_REPORT, HID_REQ_GET_REPORT);
if (ret > 0) {
- ret = min(size, ret - 1);
- memcpy(data, buf + 1, ret);
+ /* Remove the report ID from the return buffer */
+ ret--;
+ size = min(size, ret);
+ memcpy(data, buf + 1, size);
}
kfree(buf);
if (ret < 0)
hid_err(steam->hdev, "%s: error %d\n", __func__, ret);
else
- hid_dbg(steam->hdev, "Received report %*ph\n", ret, data);
- return ret;
+ hid_dbg(steam->hdev, "Received report %*ph\n", size, data);
+ if (ret < 0)
+ return ret;
+
+ if (ret < 2) {
+ hid_err(steam->hdev, "%s: reply too short\n", __func__);
+ return -EPROTO;
+ }
+ if (ret < data[1] + 2) {
+ hid_err(steam->hdev, "%s: expected %u bytes, read %i\n",
+ __func__, data[1] + 2, ret);
+ return -EPROTO;
+ }
+ return size;
}
static int steam_send_report(struct steam_device *steam,