From patchwork Mon May 23 01:42:23 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Chris J Arges X-Patchwork-Id: 9131051 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 45508607D3 for ; Mon, 23 May 2016 01:42:32 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 286E7281DB for ; Mon, 23 May 2016 01:42:32 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 1C7C8281E3; Mon, 23 May 2016 01:42:32 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, RCVD_IN_DNSWL_HI, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id B6B45281DB for ; Mon, 23 May 2016 01:42:31 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752740AbcEWBma (ORCPT ); Sun, 22 May 2016 21:42:30 -0400 Received: from mail-oi0-f68.google.com ([209.85.218.68]:36715 "EHLO mail-oi0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752728AbcEWBm3 (ORCPT ); Sun, 22 May 2016 21:42:29 -0400 Received: by mail-oi0-f68.google.com with SMTP id x130so7926903oia.3; Sun, 22 May 2016 18:42:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:to:cc:subject:date:message-id; bh=s1nr3liSCviH8nJooCK4l9DAEtfvTw5sCjQnWTwlC5A=; b=vSQst8bts7arP1DKTD4XnGULWF7Efmi500nNdzvKcChJxpFjwTLu7pZjFZNcV3/aLG B8n7C/jtKPRKtR+SZzI8TL5shICbbEke99akoQ1TEpTQg8aN2Wr8H25RpkmHMcjWjBmr rwcaxSnaJiGG6TTy/N2ScvR8N+cwjmsWRxIzKeS3tswkvSSlvQl1qkR2/BruRBbvo+dG +smEEMgvdjYK0aBkIriI7EHiNO0ydKlB3d1hI5Gdw3kUOFtNzD1mL3jBHGFXV849hRsy rIGMo1403lkXhT+XOQXPWVM8R6bZzIvp899N1zU/yflweWN3TWtHN+fqeY8QBWcSjD3N e/Lg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=s1nr3liSCviH8nJooCK4l9DAEtfvTw5sCjQnWTwlC5A=; b=JuTDyRLC9/v9zGQJugfvOgflzZdxdbGZjCOgeFhBNOUiN5SohE4ixfpsD05ZlTL2qv /diF/lTpeo/3EWoMkRCGDI/PxjrRf7/SVWFuwaHhOw1SlHlb6CoL8ttQfeSa8vUpsn5I NtsRMQkdzBVVhXEU2CJEsdd3RwbkKxe5fZHP7L9XQdTAVRhcDUmzq8F7Ed8yZltDdXtn DwqvuGbsnErMqA1oBPQFUWKJjjP4xyCWfyEyGs8R43CUzu8H2aGECfNeULw3mvUJUio3 HjDcVtMH8WBcXsiFl825tEx07/VWWHi+tkcwyQOJr04tAOkLa3x7cWznci3vEjMjb6Jp OLtA== X-Gm-Message-State: AOPr4FWmZhQAOsXBGpmoqW9jQsL0OoXrsjni8WmVOZM/vTPn9CoQ7+uKCcbp9DFYX4me7Q== X-Received: by 10.202.226.147 with SMTP id z141mr7862276oig.11.1463967748832; Sun, 22 May 2016 18:42:28 -0700 (PDT) Received: from localhost (cpe-70-112-162-223.austin.res.rr.com. [70.112.162.223]) by smtp.gmail.com with ESMTPSA id h9sm9372193obk.24.2016.05.22.18.42.28 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 22 May 2016 18:42:28 -0700 (PDT) From: Chris J Arges To: linux-input@vger.kernel.org Cc: Chris J Arges , Dmitry Torokhov , Peter Hutterer , Benjamin Tissoires , Ping Cheng , linux-kernel@vger.kernel.org Subject: [PATCH] Input: wacom_w8001 - Ignore bogus idx values in interrupt Date: Sun, 22 May 2016 20:42:23 -0500 Message-Id: <1463967746-15336-1-git-send-email-christopherarges@gmail.com> X-Mailer: git-send-email 2.7.4 Sender: linux-input-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-input@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP I've noticed crashes when using my x60t using a coreboot bios. When using the pen I can produce a crash simply by tapping a few times. This generates an event which has an idx of 0xc. This in turn crashes the machine because the array access is greater than W8001_MAX_LENGTH. This patch checks for bogus values and filters them in order to prevent crashes. Signed-off-by: Chris J Arges --- drivers/input/touchscreen/wacom_w8001.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/input/touchscreen/wacom_w8001.c b/drivers/input/touchscreen/wacom_w8001.c index bab3c6a..c858200 100644 --- a/drivers/input/touchscreen/wacom_w8001.c +++ b/drivers/input/touchscreen/wacom_w8001.c @@ -283,6 +283,15 @@ static irqreturn_t w8001_interrupt(struct serio *serio, unsigned char tmp; w8001->data[w8001->idx] = data; + + /* ignore bogus idx values */ + if (w8001->idx >= W8001_MAX_LENGTH) { + pr_info("w8001: ignored interrupt: data 0x%02x idx %d\n", data, + w8001->idx); + w8001->idx = 0; + return IRQ_HANDLED; + } + switch (w8001->idx++) { case 0: if ((data & W8001_LEAD_MASK) != W8001_LEAD_BYTE) {