-

CVE-2026-89628

HID: picolcd: clamp eeprom debugfs read to bytes actually received

In the Linux kernel, the following vulnerability has been resolved:

HID: picolcd: clamp eeprom debugfs read to bytes actually received

picolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte
supplied by the device in its REPORT_EE_DATA reply -- clamped only to
the caller's read() count:

	ret = resp->raw_data[2];
	if (ret > s)
		ret = s;
	if (copy_to_user(u, resp->raw_data+3, ret))

It never checks resp->raw_size, the number of bytes picolcd_raw_event()
actually copied into the 64-byte raw_data[] of the kmalloc'd struct
picolcd_pending. A device (or a spoofed picoLCD) returning a length byte
of 0xff, read with a count >= 255, makes copy_to_user() read past
raw_data[] into adjacent slab memory and return it to userspace through
the debugfs "eeprom" file:

	BUG: KASAN: slab-out-of-bounds in _copy_to_user
	Read of size 255 ... picolcd_debug_eeprom_read+0x214/0x2f0 [hid_picolcd]

The debug-dump path in the same file already validates the device length
byte against the received size before trusting it; this read does not.
The file is created S_IRUSR (root-only) and a crafted device is needed,
so it is neither unprivileged- nor remotely-triggerable.

Clamp the copy length to resp->raw_size - 3 (the payload actually
received, minus the 3-byte header), floored at 0 for short replies.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < 1a02056c2bf7ef9b5fd05ee6913aeeadb703c443
Status affected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < 65daa322f1021d8206f8032c4cd4c0cb2d26c7c3
Status affected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < 8dc662af019158690c470edd2e2857657f700abb
Status affected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < 4daf432c94a42e7be6aa10b012b33af5ed9bc118
Status affected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < a3e6e8d7198a9f3861861520a38b673684a1062b
Status affected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < 471f4a939c66d1d44aece2321807abf609fc9098
Status affected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < 699a3c8b56e168ca19d12722f3f5ef1d6f4b1d84
Status affected
Version 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba
Version < e9c667395ac1f8024f623250b32bae4c7af9caa0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.35
Status affected
Version 0
Version < 2.6.35
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.112
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a3e6e8d7198a9f3861861520a38b673684a1062b
https://git.kernel.org/stable/c/471f4a939c66d1d44aece2321807abf609fc9098
https://git.kernel.org/stable/c/699a3c8b56e168ca19d12722f3f5ef1d6f4b1d84
https://git.kernel.org/stable/c/e9c667395ac1f8024f623250b32bae4c7af9caa0
https://git.kernel.org/stable/c/1a02056c2bf7ef9b5fd05ee6913aeeadb703c443
https://git.kernel.org/stable/c/4daf432c94a42e7be6aa10b012b33af5ed9bc118
https://git.kernel.org/stable/c/65daa322f1021d8206f8032c4cd4c0cb2d26c7c3
https://git.kernel.org/stable/c/8dc662af019158690c470edd2e2857657f700abb