diff options
| author | szymonh <[email protected]> | 2021-09-13 22:56:25 +0200 |
|---|---|---|
| committer | szymonh <[email protected]> | 2021-09-13 22:56:25 +0200 |
| commit | 2d6407e7a5e6c99280ce11f1b02ea4b75dda133f (patch) | |
| tree | 07f32b1166c7a82697282fd8ddeb26b3934d524d | |
| parent | 43aac7074be0d14e72cb04eaddcddf1a926c6a74 (diff) | |
Enforced buffer boundaries for hid devices
| -rw-r--r-- | src/class/hid/hid_device.c | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/src/class/hid/hid_device.c b/src/class/hid/hid_device.c index 2ee80750a..55071a5ce 100644 --- a/src/class/hid/hid_device.c +++ b/src/class/hid/hid_device.c @@ -282,7 +282,7 @@ bool hidd_control_xfer_cb (uint8_t rhport, uint8_t stage, tusb_control_request_t uint8_t const report_id = tu_u16_low(request->wValue); uint8_t* report_buf = p_hid->epin_buf; - uint16_t req_len = request->wLength; + uint16_t req_len = tu_min16(request->wLength, CFG_TUD_HID_EP_BUFSIZE); uint16_t xferlen = 0; @@ -314,7 +314,7 @@ bool hidd_control_xfer_cb (uint8_t rhport, uint8_t stage, tusb_control_request_t uint8_t const report_id = tu_u16_low(request->wValue); uint8_t const* report_buf = p_hid->epout_buf; - uint16_t report_len = request->wLength; + uint16_t report_len = tu_min16(request->wLength, CFG_TUD_HID_EP_BUFSIZE); // If host request a specific Report ID, extract report ID in buffer before invoking callback if ( (report_id != HID_REPORT_TYPE_INVALID) && (report_len > 1) && (report_id == report_buf[0]) ) |
