Re: [PATCH 1/2] HID: bpf: cast size to ssize_t when checking hid_bpf_hw_request

From: Jiri Kosina

Date: Wed Sep 23 2026 - 13:25:01 EST


On Tue, 15 Sep 2026, Benjamin Tissoires wrote:

> As reported by Sashiko:
> If a transport driver encounters a hardware error and returns a negative
> error code such as -EPIPE, ret is implicitly promoted to size_t when
> compared against size. This causes the negative error code to evaluate
> as a large positive number, making the (ret > size) condition true.
>
> This silently converts the hardware error into a success return value
> and copies the unmodified buffer back, which could leave BPF programs
> operating on uninitialized or stale data.
>
> Fix this by casting size into ssize_t to return the actual negative
> error code.
>
> Link: https://lore.kernel.org/all/20260904130354.A79471F00A3D@xxxxxxxxxxxxxxx/
> Fixes: 2b658c1c442e ("HID: bpf: prevent buffer overflow in hid_hw_request")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Benjamin Tissoires <bentiss@xxxxxxxxxx>

Acked-by: Jiri Kosina <jkosina@xxxxxxxx>

--
Jiri Kosina
SUSE Labs