8.8

CVE-2026-63947

Bluetooth: HIDP: fix missing length checks in hidp_input_report()

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: HIDP: fix missing length checks in hidp_input_report()

hidp_input_report() reads keyboard and mouse payload data from an skb
without first verifying that skb->len contains enough data.

hidp_recv_intr_frame() pulls the 1-byte HIDP header before dispatching
to hidp_input_report(). If a paired device sends a truncated packet,
the handler reads beyond the valid skb data, resulting in an
out-of-bounds read of skb data. The OOB bytes may be interpreted as
phantom key presses or spurious mouse movement.

Replace the open-coded length tracking and pointer arithmetic with
skb_pull_data() calls. skb_pull_data() returns NULL if the requested
bytes are not present, eliminating the need for a manual size variable
and the separate skb->len guard.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 1f08a90013e1e632b34321334e861fcefc056505
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < cc3832b19f863e3677c5651f001a2e3795f39eb8
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < d313683d6ccdd8c01e0562270a2ae25b86d8461d
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < d7d6a81b8dd1a8d084a1b755db9406041d53adb5
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 6348dfed5b0f9c6074f14322332e97493d32fef0
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < b83dcacd2ec7fcc5a48be215f82d573759f87ec2
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 2a3ac9ee11dbb9845f3947cef4a79dba658cf6f6
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.15.*
Version 5.15.210
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.261
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1f08a90013e1e632b34321334e861fcefc056505
https://git.kernel.org/stable/c/cc3832b19f863e3677c5651f001a2e3795f39eb8
https://git.kernel.org/stable/c/d313683d6ccdd8c01e0562270a2ae25b86d8461d
https://git.kernel.org/stable/c/d7d6a81b8dd1a8d084a1b755db9406041d53adb5
https://git.kernel.org/stable/c/6348dfed5b0f9c6074f14322332e97493d32fef0
https://git.kernel.org/stable/c/b83dcacd2ec7fcc5a48be215f82d573759f87ec2
https://git.kernel.org/stable/c/2a3ac9ee11dbb9845f3947cef4a79dba658cf6f6