From 2c6fae7d7da874615d8585f6d2b16ffb673c5c9a Mon Sep 17 00:00:00 2001 From: Peter Maydell Date: Mon, 13 Jul 2026 12:34:17 +0100 Subject: [PATCH] hw/usb/dev-wacom: Don't write off end of buffer MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit In usb_wacom_handle_data() we allocate a buffer with a size determined by the transfer size requested by the guest. We then fill it in by calling either usb_mouse_poll() or usb_wacom_poll(), both of which functions take a length and return an actual length, which we pass to usb_packet_copy(). However, usb_mouse_poll() doesn't check the buffer size as it fills in the buffer, so if the guest passes an overly short transfer size then it will write off the end of the allocated buffer. Check the length is at least big enough for the minimum 3 byte packet and return nothing if it is not, as usb_wacom_poll() does. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3672 Signed-off-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daudé Message-id: 20260706182034.1003176-1-peter.maydell@linaro.org --- hw/usb/dev-wacom.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/usb/dev-wacom.c b/hw/usb/dev-wacom.c index c69e247f7b..895edcc17e 100644 --- a/hw/usb/dev-wacom.c +++ b/hw/usb/dev-wacom.c @@ -285,6 +285,10 @@ static int usb_mouse_poll(USBWacomState *s, uint8_t *buf, int len) b |= 0x04; } + if (len < 3) { + return 0; + } + buf[0] = b; buf[1] = dx; buf[2] = dy;