Re: [PATCH] HID: amd_sfh: Validate PCI BAR size before mapping
From: sashiko-bot@kernel.org
Date: 2026-08-27 06:45:17
Also in:
syzbot
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] High Severity Finding: API Usage Violation. The transport driver uses hid_input_report() instead of hid_safe_input_report(), risking out-of-bounds reads.
--
commit daa6f21fdcd011d62323dd6e5390e89dbb4f38d2
Author: Slawomir Stepien [off-list ref]
HID: amd_sfh: Validate PCI BAR size before mapping
This commit adds a check to verify that PCI BAR 2 is at least 128KB before
mapping it with pcim_iomap_regions(). This prevents an out-of-bounds memory
access during the probe function if the driver is bound to a device with a
smaller BAR 2.
Link: https://syzkaller.appspot.com/bug?extid=4eadd4dfe9e66522bae8
Link: https://syzkaller.appspot.com/ai_job?id=3bc1c45c-548f-4ab5-8243-d2c8ec321d6c
quoted hunk ↗ jump to hunk
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_common.h b/drivers/hid/amd-sfh-hid/amd_sfh_common.h index 78f830c133e5c..c0c324565bee4 100644 --- a/drivers/hid/amd-sfh-hid/amd_sfh_common.h +++ b/drivers/hid/amd-sfh-hid/amd_sfh_common.h
[ ... ]
quoted hunk ↗ jump to hunk
@@ -17,6 +17,8 @@ #define PCI_DEVICE_ID_AMD_MP2 0x15E4 #define PCI_DEVICE_ID_AMD_MP2_1_1 0x164A +#define AMD_SFH_MIN_BAR_SIZE (128 * 1024) + #define AMD_C2P_MSG(regno) (0x10500 + ((regno) * 4)) #define AMD_P2C_MSG(regno) (0x10680 + ((regno) * 4))diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c index 4b81cebdc3359..039b6ac327d3d 100644 --- a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c +++ b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
[ ... ]
quoted hunk ↗ jump to hunk
@@ -451,6 +451,16 @@ static int amd_mp2_pci_probe(struct pci_dev *pdev, const struct pci_device_id *i if (rc) return rc; + if (!(pci_resource_flags(pdev, 2) & IORESOURCE_MEM)) { + dev_err(&pdev->dev, "BAR 2 is not IORESOURCE_MEM\n"); + return -ENODEV; + } + + if (pci_resource_len(pdev, 2) < AMD_SFH_MIN_BAR_SIZE) { + dev_err(&pdev->dev, "BAR 2 is too small\n"); + return -EINVAL; + } + rc = pcim_iomap_regions(pdev, BIT(2), DRIVER_NAME); if (rc) return rc;
[Severity: High]
This is a pre-existing issue, but does this driver use the correct input
reporting API?
In drivers/hid/amd-sfh-hid/amd_sfh_client.c:amd_sfh_work():
if (node_type == HID_FEATURE_REPORT) {
report_size = mp2_ops->get_feat_rep(sensor_index, report_id,
cli_data->feature_report[current_index]);
if (report_size)
hid_input_report(cli_data->hid_sensor_hubs[current_index],
cli_data->report_type[current_index],
cli_data->feature_report[current_index], report_size, 0);
And later for HID_INPUT_REPORT:
if (report_size)
hid_input_report(cli_data->hid_sensor_hubs[current_index],
cli_data->report_type[current_index],
in_data->input_report[current_index], report_size, 0);
Also in amd_sfh_work_buffer():
hid_input_report(cli_data->hid_sensor_hubs[i], HID_INPUT_REPORT,
in_data->input_report[i], report_size, 0);
Calling hid_input_report() instead of hid_safe_input_report() in a transport
driver can lead to out-of-bounds reads in the HID core if the hardware
supplies unvalidated report sizes. Should these be changed to use
hid_safe_input_report() to provide mandatory buffer boundary checks?
--
Sashiko AI review · https://sashiko.dev/#/patchset/94704655-d654-4500-8122-b80bea9bd908@mail.kernel.org?part=1