-

CVE-2026-64427

HID: logitech-dj: Fix maxfield check in DJ short report validation

In the Linux kernel, the following vulnerability has been resolved:

HID: logitech-dj: Fix maxfield check in DJ short report validation

Commit b6a57912854e ("HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT
related user initiated OOB write") added validation for the DJ short
output report, but the error path dereferences rep->field[0] even when
rep->maxfield is zero.

Commit 8b9a097eb2fc ("HID: logitech-dj: fix wrong detection of bad
DJ_SHORT output report") made the check conditional on rep being present,
but a crafted descriptor can still create report ID 0x20 with only padding
output items. hid-core registers the report, ignores the padding field,
and leaves rep->maxfield as zero.

In that case the validation enters the rep->maxfield < 1 branch and then
dereferences rep->field[0]->report_count while printing the error message,
causing a NULL pointer dereference during probe. This is reproducible with
uhid by emulating a Logitech receiver with a padding-only DJ short output
report:

  BUG: KASAN: null-ptr-deref in logi_dj_probe+0xb1/0x754 [hid_logitech_dj]
  Read of size 4 at addr 0000000000000028 by task kworker/4:1/129
  ...
  Call Trace:
   logi_dj_probe+0xb1/0x754 [hid_logitech_dj]
   hid_device_probe+0x329/0x3f0 [hid]
   really_probe+0x162/0x570
   __device_attach+0x137/0x2c0
   bus_probe_device+0x38/0xc0
   device_add+0xa56/0xce0
   hid_add_device+0x19c/0x280 [hid]
   uhid_device_add_worker+0x2c/0xb0 [uhid]

Reject the zero-field report before printing the field report_count.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 7754ade02d0fb1caf20392baf4e02937378fd136
Version < f3790a6af9c7f47d454225cab9dc145270e48f62
Status affected
Version 2ed9638cfbf9d49bdef9b0f5ee547236c2c2f500
Version < 1215febd644c3e16f77e0f1799d89544dd57a754
Status affected
Version eeb5ad388595ca2b6624689198a057847f3a3e19
Version < 6f7f22a8d244c2e586b8eb61c7585784b62aea01
Status affected
Version 968e84f5c0dca4960580d174500e4bbf0c45dc15
Version < 95b3f23d632490b5eb285b9fcf7284f2ac8f9872
Status affected
Version ce2a731c179df8869e1969a1b2b5b9e4e1c25f8b
Version < 80c1e18473f63fd7c6a2bc9ad6f3d0a6cc4fb500
Status affected
Version bc3bba4656ad280267ea78cf845ab6b1d95b9fcd
Version < 2b70bebc709489d29a31ac2935aeffb8d5228395
Status affected
Version b6a57912854e7ea36f3b270032661140cc4209cd
Version < 7a89ad762fad53d56b7002d7ffc923a4b7f4006f
Status affected
Version b6a57912854e7ea36f3b270032661140cc4209cd
Version < 590cc4d782487632a52f37c2171bee1eeea29627
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7a89ad762fad53d56b7002d7ffc923a4b7f4006f
https://git.kernel.org/stable/c/590cc4d782487632a52f37c2171bee1eeea29627
https://git.kernel.org/stable/c/2b70bebc709489d29a31ac2935aeffb8d5228395
https://git.kernel.org/stable/c/80c1e18473f63fd7c6a2bc9ad6f3d0a6cc4fb500
https://git.kernel.org/stable/c/95b3f23d632490b5eb285b9fcf7284f2ac8f9872
https://git.kernel.org/stable/c/1215febd644c3e16f77e0f1799d89544dd57a754
https://git.kernel.org/stable/c/6f7f22a8d244c2e586b8eb61c7585784b62aea01
https://git.kernel.org/stable/c/f3790a6af9c7f47d454225cab9dc145270e48f62