Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

HID: ntrig: validate feature report details

A HID device could send a malicious feature report that would cause the
ntrig HID driver to trigger a NULL dereference during initialization:

[57383.031190] usb 3-1: New USB device found, idVendor=1b96, idProduct=0001
...
[57383.315193] BUG: unable to handle kernel NULL pointer dereference at 0000000000000030
[57383.315308] IP: [<ffffffffa08102de>] ntrig_probe+0x25e/0x420 [hid_ntrig]

CVE-2013-2896

Signed-off-by: Kees Cook <keescook@chromium.org>
Cc: stable@kernel.org
Signed-off-by: Rafi Rubin <rafi@seas.upenn.edu>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>

authored by

Kees Cook and committed by
Jiri Kosina
875b4e37 412f3010

+2 -1
+2 -1
drivers/hid/hid-ntrig.c
··· 115 115 struct hid_report *report = hdev->report_enum[HID_FEATURE_REPORT]. 116 116 report_id_hash[0x0d]; 117 117 118 - if (!report) 118 + if (!report || report->maxfield < 1 || 119 + report->field[0]->report_count < 1) 119 120 return -EINVAL; 120 121 121 122 hid_hw_request(hdev, report, HID_REQ_GET_REPORT);