From: Jiale Yao <hidden> Date: 2026-09-24 14:29:46
Roccat raw event callbacks receive the report before HID core validates
and pads its length. Seven callbacks inspect fixed-format reports without
first ensuring that the complete report was received.
Add per-driver length checks before parsing or forwarding these reports.
The first five patches protect helpers which read fixed fields, while the
konepure and ryos patches additionally prevent a fixed-size copy of a
truncated report into the Roccat character-device event stream.
Each patch is independent and fixes the driver named in its subject.
Jiale Yao (7):
HID: roccat: isku: reject short button reports
HID: roccat: koneplus: reject short button reports
HID: roccat: konepure: reject short button reports
HID: roccat: kovaplus: reject short button reports
HID: roccat: pyra: reject short button reports
HID: roccat: ryos: reject short special reports
HID: roccat: savu: reject short special reports
drivers/hid/hid-roccat-isku.c | 3 +++
drivers/hid/hid-roccat-koneplus.c | 3 +++
drivers/hid/hid-roccat-konepure.c | 3 +++
drivers/hid/hid-roccat-kovaplus.c | 3 +++
drivers/hid/hid-roccat-pyra.c | 3 +++
drivers/hid/hid-roccat-ryos.c | 3 +++
drivers/hid/hid-roccat-savu.c | 3 +++
7 files changed, 21 insertions(+)
--
2.34.1
From: Jiale Yao <hidden> Date: 2026-09-24 14:29:42
The raw event callback runs before HID core validates and zero-pads the
report. It passes the buffer to helpers which inspect data[0] and, for a
button report, read the complete struct isku_report_button. A truncated
report can therefore cause an out-of-bounds read.
Require enough data for the button report before calling either helper.
Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw-event length validation to hid-asus.
Fixes: d41c2a7011df ("HID: roccat: Add support for Isku keyboard")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <redacted>
---
drivers/hid/hid-roccat-isku.c | 3 +++
1 file changed, 3 insertions(+)
From: Jiale Yao <hidden> Date: 2026-09-24 14:29:46
The raw event callback runs before HID core validates and zero-pads the
report. It reads the report number without checking the received length
and passes matching data to roccat_report_event(), which copies a complete
struct konepure_mouse_report_button. A truncated report can therefore
cause an out-of-bounds read and expose adjacent data through the Roccat
character device.
Require a complete button report before inspecting or forwarding it.
Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw-event length validation to hid-asus.
Fixes: 8936aa31cd5f ("HID: roccat: add support for Roccat Kone Pure gaming mouse")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <redacted>
---
drivers/hid/hid-roccat-konepure.c | 3 +++
1 file changed, 3 insertions(+)
From: Jiale Yao <hidden> Date: 2026-09-24 14:30:03
The raw event callback runs before HID core validates and zero-pads the
report. It reads the report number without checking the received length
and passes matching data to roccat_report_event(), which copies a complete
struct ryos_report_special. A truncated report can therefore cause an
out-of-bounds read and expose adjacent data through the Roccat character
device.
Require a complete special report before inspecting or forwarding it.
Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw-event length validation to hid-asus.
Fixes: 6f3a19360545 ("HID: roccat: add support for Ryos MK keyboards")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <redacted>
---
drivers/hid/hid-roccat-ryos.c | 3 +++
1 file changed, 3 insertions(+)
From: Jiale Yao <hidden> Date: 2026-09-24 14:30:03
The raw event callback runs before HID core validates and zero-pads the
report. It passes the buffer to helpers which inspect data[0] and read a
complete struct pyra_mouse_event_button for button reports. A truncated
report can therefore cause an out-of-bounds read.
Require enough data for the button report before calling either helper.
Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw-event length validation to hid-asus.
Fixes: cb7cf3da0daa ("HID: roccat: add driver for Roccat Pyra mouse")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <redacted>
---
drivers/hid/hid-roccat-pyra.c | 3 +++
1 file changed, 3 insertions(+)
From: Jiale Yao <hidden> Date: 2026-09-24 14:30:04
The raw event callback runs before HID core validates and zero-pads the
report. It passes the buffer to a helper which inspects data[0] and, for a
special report, reads the complete struct savu_mouse_report_special. A
truncated report can therefore cause an out-of-bounds read.
Require enough data for the special report before calling the helper.
Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw-event length validation to hid-asus.
Fixes: 6a2a6390cf09 ("HID: roccat: add support for Roccat Savu")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <redacted>
---
drivers/hid/hid-roccat-savu.c | 3 +++
1 file changed, 3 insertions(+)
From: Jiale Yao <hidden> Date: 2026-09-24 14:30:06
The raw event callback runs before HID core validates and zero-pads the
report. It passes the buffer to helpers which inspect data[0] and read a
complete struct kovaplus_mouse_report_button for button reports. A
truncated report can therefore cause an out-of-bounds read.
Require enough data for the button report before calling either helper.
Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw-event length validation to hid-asus.
Fixes: 0e70f97f257e ("HID: roccat: Add support for Kova[+] mouse")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <redacted>
---
drivers/hid/hid-roccat-kovaplus.c | 3 +++
1 file changed, 3 insertions(+)
From: Jiale Yao <hidden> Date: 2026-09-24 14:30:30
The raw event callback runs before HID core validates and zero-pads the
report. It passes the buffer to helpers which inspect data[0] and, for a
button report, read the complete struct koneplus_mouse_report_button. A
truncated report can therefore cause an out-of-bounds read.
Require enough data for the button report before calling either helper.
Commit 47669bec44fe ("HID: asus: refactor the two workqueues and init
sequence") added the same kind of raw-event length validation to hid-asus.
Fixes: 47dbdbffe15b ("HID: roccat: Add support for Roccat Kone[+] v2")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <redacted>
---
drivers/hid/hid-roccat-koneplus.c | 3 +++
1 file changed, 3 insertions(+)