Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit bb83a744 authored by Jeff LaBundy's avatar Jeff LaBundy Committed by Greg Kroah-Hartman
Browse files

Input: add bounds checking to input_set_capability()



[ Upstream commit 409353cbe9fe48f6bc196114c442b1cff05a39bc ]

Update input_set_capability() to prevent kernel panic in case the
event code exceeds the bitmap for the given event type.

Suggested-by: default avatarTomasz Moń <tomasz.mon@camlingroup.com>
Signed-off-by: default avatarJeff LaBundy <jeff@labundy.com>
Reviewed-by: default avatarTomasz Moń <tomasz.mon@camlingroup.com>
Link: https://lore.kernel.org/r/20220320032537.545250-1-jeff@labundy.com


Signed-off-by: default avatarDmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
parent 4fd39669
Loading
Loading
Loading
Loading
+19 −0
Original line number Original line Diff line number Diff line
@@ -47,6 +47,17 @@ static DEFINE_MUTEX(input_mutex);


static const struct input_value input_value_sync = { EV_SYN, SYN_REPORT, 1 };
static const struct input_value input_value_sync = { EV_SYN, SYN_REPORT, 1 };


static const unsigned int input_max_code[EV_CNT] = {
	[EV_KEY] = KEY_MAX,
	[EV_REL] = REL_MAX,
	[EV_ABS] = ABS_MAX,
	[EV_MSC] = MSC_MAX,
	[EV_SW] = SW_MAX,
	[EV_LED] = LED_MAX,
	[EV_SND] = SND_MAX,
	[EV_FF] = FF_MAX,
};

static inline int is_event_supported(unsigned int code,
static inline int is_event_supported(unsigned int code,
				     unsigned long *bm, unsigned int max)
				     unsigned long *bm, unsigned int max)
{
{
@@ -1978,6 +1989,14 @@ EXPORT_SYMBOL(input_get_timestamp);
 */
 */
void input_set_capability(struct input_dev *dev, unsigned int type, unsigned int code)
void input_set_capability(struct input_dev *dev, unsigned int type, unsigned int code)
{
{
	if (type < EV_CNT && input_max_code[type] &&
	    code > input_max_code[type]) {
		pr_err("%s: invalid code %u for type %u\n", __func__, code,
		       type);
		dump_stack();
		return;
	}

	switch (type) {
	switch (type) {
	case EV_KEY:
	case EV_KEY:
		__set_bit(code, dev->keybit);
		__set_bit(code, dev->keybit);