Thread (3 messages) 3 messages, 2 authors, 9d ago

Re: [PATCH] Input: wacom_w8001 - validate index before storing data byte

From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Date: 2026-09-20 04:02:09
Also in: lkml

Hi Muhammad,

On Sun, Sep 20, 2026 at 12:21:53AM +0500, Muhammad Bilal wrote:
w8001_interrupt() stores every incoming byte at w8001->data[w8001->idx]
before the following switch on w8001->idx++ has a chance to detect an
invalid packet and reset idx. The switch only resets idx for the
specific packet lengths it recognizes; once idx has advanced past all
of those (W8001_PKTLEN_TOUCH2FG - 1 at most), any further byte falls
into default, where idx is only reset for pen-only devices without a
touch_dev (the ThinkPad X60 workaround). A touch-capable device fed a
malformed or overlong packet therefore has nothing to stop idx from
growing without bound, and w8001->data[w8001->idx] = data runs past
the end of the W8001_MAX_LENGTH-sized array.
This analysis does not match the code.

w8001->idx starts at 0 and is incremented by 1 on each invocation via
switch (w8001->idx++). To advance past W8001_PKTLEN_TOUCH2FG - 1 (12),
w8001->idx would first have to pass through 12, which matches:

	/* 2 finger touch packet */
	case W8001_PKTLEN_TOUCH2FG - 1:
		w8001->idx = 0;
		parse_multi_touch(w8001);
		break;

Unlike the shorter packet length cases, this case has no conditional
break and unconditionally resets w8001->idx to 0. Since W8001_MAX_LENGTH
is 13 (matching W8001_PKTLEN_TOUCH2FG), w8001->idx is always in the
[0, 12] range when entering w8001_interrupt().

As a result, w8001->idx >= W8001_MAX_LENGTH is unreachable and the array
store cannot go out of bounds.

Thanks.

-- 
Dmitry
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help