8.8
CVE-2026-64366
- EPSS 0.25%
- Veröffentlicht 25.07.2026 08:50:20
- Zuletzt bearbeitet 17.08.2026 05:17:38
- CVE-Watchlists
- Unerledigt
HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
wacom_wac_queue_insert() calls kfifo_skip() in a loop when the kfifo
doesn't have enough space for the incoming report. If the kfifo is
empty, kfifo_skip() reads stale data left in the kmalloc'd buffer
via __kfifo_peek_n() and interprets it as a record length, advancing
fifo->out by that garbage value. This corrupts the internal kfifo
state, causing kfifo_unused() to return a value much larger than the
actual buffer size, which bypasses __kfifo_in_r()'s guard:
if (len + recsize > kfifo_unused(fifo))
return 0;
kfifo_copy_in() then performs an out-of-bounds memcpy, writing up to
3842 bytes past the 256-byte buffer.
Add a !kfifo_is_empty() condition to the while loop so kfifo_skip()
is never called on an empty fifo, and check the return value of
kfifo_in() to reject reports that are too large for the fifo.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
5e013ad206895e72d7da41bc1ae89d8cb499c3aa
Version <
ca899a926c11a59211b764b0155d9a1cdcc32b81
Status
affected
Version
5e013ad206895e72d7da41bc1ae89d8cb499c3aa
Version <
57bdd10ad50d68341f500a7b330f0d8949e510ec
Status
affected
Version
5e013ad206895e72d7da41bc1ae89d8cb499c3aa
Version <
6b3014ec0e9a390ca563030b2d7689921f0daef5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.15
Status
affected
Version
0
Version <
6.15
Status
unaffected
Version <=
6.18.*
Version
6.18.39
Status
unaffected
Version <=
7.1.*
Version
7.1.4
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.168 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/ca899a926c11a59211b764b0155d9a1cdcc32b81
https://git.kernel.org/stable/c/57bdd10ad50d68341f500a7b330f0d8949e510ec
https://git.kernel.org/stable/c/6b3014ec0e9a390ca563030b2d7689921f0daef5