CVE-2026-89621
In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: validate report size in mcp2221_raw_event() mcp2221_raw_event() never validates the size of incoming HID reports. In the MCP2221_I2C_GET_DATA path it trusts the device-supplied data[3] as the copy length without checking that 4 + data[3] bytes actually exist in the received report. A malicious or misbehaving USB device can send a short report with a large data[3], causing the memcpy to read past the valid report data in the HID transfer buffer and leak uninitialized kernel memory back to userspace through the I2C/SMBus read path. Add a minimum size check at entry and validate that the source range fits within the received report before the copy.
Açıklama ve Etki
In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: validate report size in mcp2221_raw_event() mcp2221_raw_event() never validates the size of incoming HID reports. In the MCP2221_I2C_GET_DATA path it trusts the device-supplied data[3] as the copy length without checking that 4 + data[3] bytes actually exist in the received report. A malicious or misbehaving USB device can send a short report with a large data[3], causing the memcpy to read past the valid report data in the HID transfer buffer and leak uninitialized kernel memory back to userspace through the I2C/SMBus read path. Add a minimum size check at entry and validate that the source range fits within the received report before the copy.
Referanslar
- https://git.kernel.org/stable/c/127de5919820f88a9d55e8371ad4ac49f625f4c5
- https://git.kernel.org/stable/c/2c9a6998c19503626c57a2267bf279e204113079
- https://git.kernel.org/stable/c/7c18fb36708a97ff6772825cc087b6d537bbf0d5
- https://git.kernel.org/stable/c/bdc6a3af0dd734a326acdb7d6401a3b6a9f4f149
- https://git.kernel.org/stable/c/b2c67dc0e30c308647bbd9b9e5d69a44c9d2733d
- https://git.kernel.org/stable/c/c1c508e8923911cb458234997e55b7a4b9aa066f
- https://git.kernel.org/stable/c/cb38b1f149b7143355b37e86c841acf0076e5c2a
- https://git.kernel.org/stable/c/fffcfa367072628c3144cca17d2a3c3c9e50c057
Güvenli Doğrulama Notu
Bu sayfa saldırı gerçekleştiren payload'lar çalıştırmaz. Doğrulama; etkilenen ürün/sürümün envanterden kontrol edilmesi, üretici güvenlik duyurusunun incelenmesi ve güncellemenin uygulanması üzerinden yapılmalıdır.