7.8

CVE-2026-89619

HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer

In the Linux kernel, the following vulnerability has been resolved:

HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer

quickspi_hid_raw_request() receives the caller's buffer length in len, but
quickspi_get_report() never sees it and copies the whole device-supplied
response into buf regardless:

    memcpy(buf, qsdev->report_buf, qsdev->report_len);

qsdev->report_len comes from the input report the touch controller returns,
while buf is sized to whatever the caller asked hidraw for through
HIDIOCGFEATURE or HIDIOCGINPUT.  A response larger than that overflows buf
with device-controlled content.

The intel-quicki2c sibling already passes the caller length down to
quicki2c_get_report() and validates the response against it before the
copy.  Do the same here.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4138f21115aec3ebae7805ec3407c72d93558023
Version < 72706b44b665679d7d60a488d8776a911f1a93f3
Status affected
Version 4138f21115aec3ebae7805ec3407c72d93558023
Version < 54e0bafc0653bdf2a6c5f5f8ad8787a820d98663
Status affected
Version 4138f21115aec3ebae7805ec3407c72d93558023
Version < 035ec4a71cb8020a927c123bbe75c2f88d614986
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/72706b44b665679d7d60a488d8776a911f1a93f3
https://git.kernel.org/stable/c/54e0bafc0653bdf2a6c5f5f8ad8787a820d98663
https://git.kernel.org/stable/c/035ec4a71cb8020a927c123bbe75c2f88d614986