-

CVE-2026-97538

hwmon: (asus_rog_ryujin) Validate HID report lengths

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (asus_rog_ryujin) Validate HID report lengths

rog_ryujin_raw_event() parses response headers and payload fields without
first checking that they are present in the received report. A short report
can therefore make the driver consume uninitialized bytes from the HID
transport buffer and expose them as sensor values through sysfs.

Validate the response header and the fields used by each response type
before parsing them.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ed3e03790c5c9f29f032dde9bb784e198984a759
Version < 1caa5f9399ff107a8fa221b1eaca0a9e729d3758
Status affected
Version ed3e03790c5c9f29f032dde9bb784e198984a759
Version < 8042312e73c50de82634ce63eae7cf219464b481
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.077
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1caa5f9399ff107a8fa221b1eaca0a9e729d3758
https://git.kernel.org/stable/c/8042312e73c50de82634ce63eae7cf219464b481