summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorHa Thach <[email protected]>2021-09-23 13:31:46 +0700
committerGitHub <[email protected]>2021-09-23 13:31:46 +0700
commit4766e7f3481434bdc6c3b29c402ccd56d4b3a216 (patch)
tree500ea392770bcdb2b24c1288c62fbba5082757a9 /src
parent3e569f8e79160538e1b055aba352246abb6c3dd0 (diff)
parent2d6407e7a5e6c99280ce11f1b02ea4b75dda133f (diff)
Merge pull request #1093 from szymonh/master
Enforced buffer boundaries for hid devices
Diffstat (limited to 'src')
-rw-r--r--src/class/hid/hid_device.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/src/class/hid/hid_device.c b/src/class/hid/hid_device.c
index 2ee80750a..55071a5ce 100644
--- a/src/class/hid/hid_device.c
+++ b/src/class/hid/hid_device.c
@@ -282,7 +282,7 @@ bool hidd_control_xfer_cb (uint8_t rhport, uint8_t stage, tusb_control_request_t
uint8_t const report_id = tu_u16_low(request->wValue);
uint8_t* report_buf = p_hid->epin_buf;
- uint16_t req_len = request->wLength;
+ uint16_t req_len = tu_min16(request->wLength, CFG_TUD_HID_EP_BUFSIZE);
uint16_t xferlen = 0;
@@ -314,7 +314,7 @@ bool hidd_control_xfer_cb (uint8_t rhport, uint8_t stage, tusb_control_request_t
uint8_t const report_id = tu_u16_low(request->wValue);
uint8_t const* report_buf = p_hid->epout_buf;
- uint16_t report_len = request->wLength;
+ uint16_t report_len = tu_min16(request->wLength, CFG_TUD_HID_EP_BUFSIZE);
// If host request a specific Report ID, extract report ID in buffer before invoking callback
if ( (report_id != HID_REPORT_TYPE_INVALID) && (report_len > 1) && (report_id == report_buf[0]) )