-
CVE-2026-89628
- EPSS 0.21%
- Veröffentlicht 11.09.2026 19:45:24
- Zuletzt bearbeitet 14.09.2026 13:19:16
- Erkennungen
HID: picolcd: clamp eeprom debugfs read to bytes actually received
In the Linux kernel, the following vulnerability has been resolved: HID: picolcd: clamp eeprom debugfs read to bytes actually received picolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte supplied by the device in its REPORT_EE_DATA reply -- clamped only to the caller's read() count: ret = resp->raw_data[2]; if (ret > s) ret = s; if (copy_to_user(u, resp->raw_data+3, ret)) It never checks resp->raw_size, the number of bytes picolcd_raw_event() actually copied into the 64-byte raw_data[] of the kmalloc'd struct picolcd_pending. A device (or a spoofed picoLCD) returning a length byte of 0xff, read with a count >= 255, makes copy_to_user() read past raw_data[] into adjacent slab memory and return it to userspace through the debugfs "eeprom" file: BUG: KASAN: slab-out-of-bounds in _copy_to_user Read of size 255 ... picolcd_debug_eeprom_read+0x214/0x2f0 [hid_picolcd] The debug-dump path in the same file already validates the device length byte against the received size before trusting it; this read does not. The file is created S_IRUSR (root-only) and a crafted device is needed, so it is neither unprivileged- nor remotely-triggerable. Clamp the copy length to resp->raw_size - 3 (the payload actually received, minus the 3-byte header), floored at 0 for short replies.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
1a02056c2bf7ef9b5fd05ee6913aeeadb703c443
Status
affected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
65daa322f1021d8206f8032c4cd4c0cb2d26c7c3
Status
affected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
8dc662af019158690c470edd2e2857657f700abb
Status
affected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
4daf432c94a42e7be6aa10b012b33af5ed9bc118
Status
affected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
a3e6e8d7198a9f3861861520a38b673684a1062b
Status
affected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
471f4a939c66d1d44aece2321807abf609fc9098
Status
affected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
699a3c8b56e168ca19d12722f3f5ef1d6f4b1d84
Status
affected
Version
9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version <
e9c667395ac1f8024f623250b32bae4c7af9caa0
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.35
Status
affected
Version
0
Version <
2.6.35
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.112 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a3e6e8d7198a9f3861861520a38b673684a1062b
https://git.kernel.org/stable/c/471f4a939c66d1d44aece2321807abf609fc9098
https://git.kernel.org/stable/c/699a3c8b56e168ca19d12722f3f5ef1d6f4b1d84
https://git.kernel.org/stable/c/e9c667395ac1f8024f623250b32bae4c7af9caa0
https://git.kernel.org/stable/c/1a02056c2bf7ef9b5fd05ee6913aeeadb703c443
https://git.kernel.org/stable/c/4daf432c94a42e7be6aa10b012b33af5ed9bc118
https://git.kernel.org/stable/c/65daa322f1021d8206f8032c4cd4c0cb2d26c7c3
https://git.kernel.org/stable/c/8dc662af019158690c470edd2e2857657f700abb