[PATCH v3 1/2] HID: uclogic: fix UAF on inrange_timer at teardown and probe error
From: Doruk Tan Ozturk <hidden>
Date: 2026-07-13 21:59:54
Also in:
lkml, stable
Subsystem:
hid core layer, the rest · Maintainers:
Jiri Kosina, Benjamin Tissoires, Linus Torvalds
uclogic_probe() arms a per-device timer whose callback uclogic_inrange_timeout() dereferences drvdata->pen_input, and uclogic_raw_event_pen() re-arms it with a 100 ms timeout on every in-range pen report. uclogic_remove() drained the timer with timer_delete_sync() before hid_hw_stop(). timer_delete_sync() does not block re-arming: a pen report delivered before hid_hw_stop() kills the URBs can re-arm the timer after it was drained. hid_hw_stop() then frees the hidinput pen_input (via hidinput_disconnect() -> input_unregister_device()), and the pending timer fires on freed memory. Use timer_shutdown_sync() instead, still before hid_hw_stop(). It drains the callback while pen_input is still valid and permanently blocks re-arming, so an in-flight raw_event cannot revive the timer; hid_hw_stop() then frees pen_input with the timer already dead. The probe error path had the same exposure: if hid_hw_start() started I/O and then failed, raw_event may have armed the timer, which would fire on the devm-freed drvdata after probe returns. Shut the timer down there too. Unlike letsketch, whose input devices are devm-allocated and outlive hid_hw_stop(), uclogic's pen_input is freed inside hid_hw_stop(), so the timer must be shut down before it rather than after. Found by 0sec (https://0sec.ai). Fixes: 01309e29eb95 ("HID: uclogic: Support in-range reporting emulation") Cc: stable@vger.kernel.org Assisted-by: 0sec Signed-off-by: Doruk Tan Ozturk <redacted> --- v3: resend as a 2-patch series. 1/2 is the v2 timer fix, unchanged. 2/2 adds the desc_ptr leak fix in the probe error path, flagged by the Sashiko AI review on v2. No functional change to this patch since v2. v2: shut the timer down on the probe error path too, and clarify in the commit message why uclogic differs from the letsketch precedent (pen_input is freed inside hid_hw_stop(), so the timer must be shut down before it). drivers/hid/hid-uclogic-core.c | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-)
diff --git a/drivers/hid/hid-uclogic-core.c b/drivers/hid/hid-uclogic-core.c
index b73f09d26688..d74f98efa879 100644
--- a/drivers/hid/hid-uclogic-core.c
+++ b/drivers/hid/hid-uclogic-core.c@@ -267,6 +267,13 @@ static int uclogic_probe(struct hid_device *hdev, /* Assume "remove" might not be called if "probe" failed */ if (params_initialized) uclogic_params_cleanup(&drvdata->params); + /* + * If hid_hw_start() started I/O and then failed, raw_event may have + * armed the timer; shut it down so it cannot fire on the devm-freed + * drvdata after probe returns. + */ + if (drvdata) + timer_shutdown_sync(&drvdata->inrange_timer); return rc; }
@@ -548,7 +555,15 @@ static void uclogic_remove(struct hid_device *hdev) { struct uclogic_drvdata *drvdata = hid_get_drvdata(hdev); - timer_delete_sync(&drvdata->inrange_timer); + /* + * timer_delete_sync() does not prevent re-arming, so a pen report + * delivered before hid_hw_stop() kills the URBs could re-arm the + * timer; hid_hw_stop() then frees the hidinput pen_input and the + * pending timer fires on freed memory. timer_shutdown_sync() drains + * the callback while pen_input is still valid and permanently blocks + * re-arming, so an in-flight raw_event cannot revive it. + */ + timer_shutdown_sync(&drvdata->inrange_timer); hid_hw_stop(hdev); kfree(drvdata->desc_ptr); uclogic_params_cleanup(&drvdata->params);
--
2.43.0