7.8
CVE-2026-64273
- EPSS 0.16%
- Veröffentlicht 25.07.2026 08:49:19
- Zuletzt bearbeitet 17.08.2026 05:17:26
- CVE-Watchlists
- Unerledigt
Input: iforce - bound the device-reported force-feedback effect index
In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - bound the device-reported force-feedback effect index
iforce_process_packet() handles a status report (packet id 0x02) by
taking a force-feedback effect index straight from the device wire and
using it to address the per-effect state array:
i = data[1] & 0x7f;
if (data[1] & 0x80) {
if (!test_and_set_bit(FF_CORE_IS_PLAYED,
iforce->core_effects[i].flags))
...
} else if (test_and_clear_bit(FF_CORE_IS_PLAYED,
iforce->core_effects[i].flags)) {
...
}
The index is masked only with 0x7f, so it ranges 0..127, but
core_effects[] holds only IFORCE_EFFECTS_MAX (32) entries. For an index
of 32..127 the test_and_set_bit()/test_and_clear_bit() is an
out-of-bounds single-bit read-modify-write past the array. core_effects[]
is the second-to-last member of struct iforce, so the write lands in the
trailing members and beyond the embedding kzalloc()'d iforce_serio /
iforce_usb object.
data[1] is unvalidated device payload on both transports (the USB
interrupt endpoint and serio), and the status path is not gated on force
feedback being present, so a malicious or counterfeit device can set or
clear a bit at an attacker-chosen offset past the object.
Reject an out-of-range index instead of indexing with it. Bound against
the array dimension IFORCE_EFFECTS_MAX rather than dev->ff->max_effects so
the check guarantees memory safety regardless of how many effects the
device registered. A legitimate "effect started/stopped" status always
carries an index below IFORCE_EFFECTS_MAX, so well-formed devices are
unaffected; the neighbouring mark_core_as_ready() loop is already bounded
and is left untouched.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.12.1 < 5.10.261
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.212
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.178
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.145
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.96
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.39
Linux ≫ Linux Kernel Version >= 6.19 < 7.1.4
Linux ≫ Linux Kernel Version2.6.12 Update-
Linux ≫ Linux Kernel Version2.6.12 Updaterc2
Linux ≫ Linux Kernel Version2.6.12 Updaterc3
Linux ≫ Linux Kernel Version2.6.12 Updaterc4
Linux ≫ Linux Kernel Version2.6.12 Updaterc5
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
https://git.kernel.org/stable/c/b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310
https://git.kernel.org/stable/c/d10b0507fa0f5b46764b178e3271f9012f2df677
https://git.kernel.org/stable/c/6c0f2901c9d325d4a0574c4237fd507810d225ff
https://git.kernel.org/stable/c/c21295616a8a52b9a5f18cd4ca8c73030eda3d4f
https://git.kernel.org/stable/c/e5fa31f0550b55d80045669ae9080dd5b88abffa
https://git.kernel.org/stable/c/70019779325f2bb5f5a4098e91e79c655f50fcef
https://git.kernel.org/stable/c/a40250f97c312e000e3616c9074022311a0efbc3
https://git.kernel.org/stable/c/0e9943d2e4c63496b6ca84bc66fd3c71d40558e2