hw/usb/dev-wacom: Don't write off end of buffer

In usb_wacom_handle_data() we allocate a buffer with a size
determined by the transfer size requested by the guest.  We then fill
it in by calling either usb_mouse_poll() or usb_wacom_poll(), both of
which functions take a length and return an actual length, which we
pass to usb_packet_copy().  However, usb_mouse_poll() doesn't check
the buffer size as it fills in the buffer, so if the guest passes an
overly short transfer size then it will write off the end of the
allocated buffer.

Check the length is at least big enough for the minimum 3 byte
packet and return nothing if it is not, as usb_wacom_poll() does.

Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3672
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260706182034.1003176-1-peter.maydell@linaro.org
This commit is contained in:
Peter Maydell
2026-07-13 12:34:17 +01:00
parent 4571c79c57
commit 2c6fae7d7d

View File

@@ -285,6 +285,10 @@ static int usb_mouse_poll(USBWacomState *s, uint8_t *buf, int len)
b |= 0x04; b |= 0x04;
} }
if (len < 3) {
return 0;
}
buf[0] = b; buf[0] = b;
buf[1] = dx; buf[1] = dx;
buf[2] = dy; buf[2] = dy;