Re: [PATCH] Input: wacom_w8001 - validate index before storing data byte
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Date: 2026-09-20 04:02:09
Also in:
lkml
Hi Muhammad, On Sun, Sep 20, 2026 at 12:21:53AM +0500, Muhammad Bilal wrote:
w8001_interrupt() stores every incoming byte at w8001->data[w8001->idx] before the following switch on w8001->idx++ has a chance to detect an invalid packet and reset idx. The switch only resets idx for the specific packet lengths it recognizes; once idx has advanced past all of those (W8001_PKTLEN_TOUCH2FG - 1 at most), any further byte falls into default, where idx is only reset for pen-only devices without a touch_dev (the ThinkPad X60 workaround). A touch-capable device fed a malformed or overlong packet therefore has nothing to stop idx from growing without bound, and w8001->data[w8001->idx] = data runs past the end of the W8001_MAX_LENGTH-sized array.
This analysis does not match the code. w8001->idx starts at 0 and is incremented by 1 on each invocation via switch (w8001->idx++). To advance past W8001_PKTLEN_TOUCH2FG - 1 (12), w8001->idx would first have to pass through 12, which matches: /* 2 finger touch packet */ case W8001_PKTLEN_TOUCH2FG - 1: w8001->idx = 0; parse_multi_touch(w8001); break; Unlike the shorter packet length cases, this case has no conditional break and unconditionally resets w8001->idx to 0. Since W8001_MAX_LENGTH is 13 (matching W8001_PKTLEN_TOUCH2FG), w8001->idx is always in the [0, 12] range when entering w8001_interrupt(). As a result, w8001->idx >= W8001_MAX_LENGTH is unreachable and the array store cannot go out of bounds. Thanks. -- Dmitry