Skip to content

Commit 26fae72

Browse files
committed
Merge: CVE-2025-21746: Input: synaptics - fix crash when enabling pass-through port
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9/-/merge_requests/6451 JIRA: https://issues.redhat.com/browse/RHEL-81215 CVE: CVE-2025-21746 ``` commit 08bd5b7 Author: Dmitry Torokhov <dmitry.torokhov@gmail.com> Date: Fri Jan 17 09:23:40 2025 -0800 Input: synaptics - fix crash when enabling pass-through port When enabling a pass-through port an interrupt might come before psmouse driver binds to the pass-through port. However synaptics sub-driver tries to access psmouse instance presumably associated with the pass-through port to figure out if only 1 byte of response or entire protocol packet needs to be forwarded to the pass-through port and may crash if psmouse instance has not been attached to the port yet. Fix the crash by introducing open() and close() methods for the port and check if the port is open before trying to access psmouse instance. Because psmouse calls serio_open() only after attaching psmouse instance to serio port instance this prevents the potential crash. Reported-by: Takashi Iwai <tiwai@suse.de> Fixes: 100e169 ("Input: libps2 - attach ps2dev instances as serio port's drvdata") Link: https://bugzilla.suse.com/show_bug.cgi?id=1219522 Cc: stable@vger.kernel.org Reviewed-by: Takashi Iwai <tiwai@suse.de> Link: https://lore.kernel.org/r/Z4qSHORvPn7EU2j1@google.com Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>``` Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> --- <small>Created 2025-02-27 14:14 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://gitlab.com/cki-project/kernel-workflow/-/issues/new?issue%5Btitle%5D=backporter%20webhook%20issue)</small> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Benjamin Tissoires <benjamin.tissoires@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: Augusto Caringi <acaringi@redhat.com>
2 parents 01e5990 + 2619f50 commit 26fae72

File tree

3 files changed

+46
-14
lines changed

3 files changed

+46
-14
lines changed

drivers/input/mouse/synaptics.c

Lines changed: 42 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -667,23 +667,50 @@ static void synaptics_pt_stop(struct serio *serio)
667667
serio_continue_rx(parent->ps2dev.serio);
668668
}
669669

670+
static int synaptics_pt_open(struct serio *serio)
671+
{
672+
struct psmouse *parent = psmouse_from_serio(serio->parent);
673+
struct synaptics_data *priv = parent->private;
674+
675+
guard(serio_pause_rx)(parent->ps2dev.serio);
676+
priv->pt_port_open = true;
677+
678+
return 0;
679+
}
680+
681+
static void synaptics_pt_close(struct serio *serio)
682+
{
683+
struct psmouse *parent = psmouse_from_serio(serio->parent);
684+
struct synaptics_data *priv = parent->private;
685+
686+
guard(serio_pause_rx)(parent->ps2dev.serio);
687+
priv->pt_port_open = false;
688+
}
689+
670690
static int synaptics_is_pt_packet(u8 *buf)
671691
{
672692
return (buf[0] & 0xFC) == 0x84 && (buf[3] & 0xCC) == 0xC4;
673693
}
674694

675-
static void synaptics_pass_pt_packet(struct serio *ptport, u8 *packet)
695+
static void synaptics_pass_pt_packet(struct synaptics_data *priv, u8 *packet)
676696
{
677-
struct psmouse *child = psmouse_from_serio(ptport);
697+
struct serio *ptport;
678698

679-
if (child && child->state == PSMOUSE_ACTIVATED) {
680-
serio_interrupt(ptport, packet[1], 0);
681-
serio_interrupt(ptport, packet[4], 0);
682-
serio_interrupt(ptport, packet[5], 0);
683-
if (child->pktsize == 4)
684-
serio_interrupt(ptport, packet[2], 0);
685-
} else {
686-
serio_interrupt(ptport, packet[1], 0);
699+
ptport = priv->pt_port;
700+
if (!ptport)
701+
return;
702+
703+
serio_interrupt(ptport, packet[1], 0);
704+
705+
if (priv->pt_port_open) {
706+
struct psmouse *child = psmouse_from_serio(ptport);
707+
708+
if (child->state == PSMOUSE_ACTIVATED) {
709+
serio_interrupt(ptport, packet[4], 0);
710+
serio_interrupt(ptport, packet[5], 0);
711+
if (child->pktsize == 4)
712+
serio_interrupt(ptport, packet[2], 0);
713+
}
687714
}
688715
}
689716

@@ -722,6 +749,8 @@ static void synaptics_pt_create(struct psmouse *psmouse)
722749
serio->write = synaptics_pt_write;
723750
serio->start = synaptics_pt_start;
724751
serio->stop = synaptics_pt_stop;
752+
serio->open = synaptics_pt_open;
753+
serio->close = synaptics_pt_close;
725754
serio->parent = psmouse->ps2dev.serio;
726755

727756
psmouse->pt_activate = synaptics_pt_activate;
@@ -1218,11 +1247,10 @@ static psmouse_ret_t synaptics_process_byte(struct psmouse *psmouse)
12181247

12191248
if (SYN_CAP_PASS_THROUGH(priv->info.capabilities) &&
12201249
synaptics_is_pt_packet(psmouse->packet)) {
1221-
if (priv->pt_port)
1222-
synaptics_pass_pt_packet(priv->pt_port,
1223-
psmouse->packet);
1224-
} else
1250+
synaptics_pass_pt_packet(priv, psmouse->packet);
1251+
} else {
12251252
synaptics_process_packet(psmouse);
1253+
}
12261254

12271255
return PSMOUSE_FULL_PACKET;
12281256
}

drivers/input/mouse/synaptics.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -188,6 +188,7 @@ struct synaptics_data {
188188
bool disable_gesture; /* disable gestures */
189189

190190
struct serio *pt_port; /* Pass-through serio port */
191+
bool pt_port_open;
191192

192193
/*
193194
* Last received Advanced Gesture Mode (AGM) packet. An AGM packet

include/linux/serio.h

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@
66
#define _SERIO_H
77

88

9+
#include <linux/cleanup.h>
910
#include <linux/types.h>
1011
#include <linux/interrupt.h>
1112
#include <linux/list.h>
@@ -161,4 +162,6 @@ static inline void serio_continue_rx(struct serio *serio)
161162
spin_unlock_irq(&serio->lock);
162163
}
163164

165+
DEFINE_GUARD(serio_pause_rx, struct serio *, serio_pause_rx(_T), serio_continue_rx(_T))
166+
164167
#endif

0 commit comments

Comments
 (0)