summaryrefslogtreecommitdiff
path: root/src/class
diff options
context:
space:
mode:
authorZixun LI <[email protected]>2026-06-23 19:18:13 +0200
committerGitHub <[email protected]>2026-06-23 19:18:13 +0200
commite7cf9583f84731770316cf87f09685ec53d4d8ed (patch)
tree589ddbddb42bb35788187054525ada153f9b5e3a /src/class
parent33a340dbbefbf75b88d4e8055ea8814b4e55c8d3 (diff)
parent9f8812f81bdd323399abd6e18c2567fed3efebc5 (diff)
Merge pull request #3698 from dxbjavid/hid-report-desc-bounds
bound item size to remaining length in hid report descriptor parser
Diffstat (limited to 'src/class')
-rw-r--r--src/class/hid/hid_host.c11
1 files changed, 10 insertions, 1 deletions
diff --git a/src/class/hid/hid_host.c b/src/class/hid/hid_host.c
index fc7704258..29bcae99f 100644
--- a/src/class/hid/hid_host.c
+++ b/src/class/hid/hid_host.c
@@ -704,6 +704,10 @@ uint8_t tuh_hid_parse_report_descriptor(tuh_hid_report_info_t* report_info_arr,
size = 4; // HID 1.11 6.2.2.2 3 is 4 bytes
}
+ // item data must fit in the remaining descriptor; a truncated item would
+ // read past the buffer and underflow desc_len below
+ if (size > desc_len) break;
+
uint8_t const data8 = (size > 0) ? desc_report[0] : 0;
TU_LOG(3, "tag = %d, type = %d, size = %d, data = ", tag, type, size);
@@ -738,7 +742,12 @@ uint8_t tuh_hid_parse_report_descriptor(tuh_hid_report_info_t* report_info_arr,
switch (tag) {
case RI_GLOBAL_USAGE_PAGE:
// only take in account the "usage page" before REPORT ID
- if (ri_collection_depth == 0) memcpy(&info->usage_page, desc_report, size);
+ if (ri_collection_depth == 0) {
+ // zero-extend: a shorter payload must not leave a stale high byte
+ // from a previous usage page item in the same report
+ info->usage_page = 0;
+ memcpy(&info->usage_page, desc_report, TU_MIN(size, sizeof(info->usage_page)));
+ }
break;
case RI_GLOBAL_LOGICAL_MIN: break;