PT-2026-61264 · Linux · Linux
CVE-2026-63947
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: fix missing length checks in hidp input report()
hidp input report() reads keyboard and mouse payload data from an skb
without first verifying that skb->len contains enough data.
hidp recv intr frame() pulls the 1-byte HIDP header before dispatching
to hidp input report(). If a paired device sends a truncated packet,
the handler reads beyond the valid skb data, resulting in an
out-of-bounds read of skb data. The OOB bytes may be interpreted as
phantom key presses or spurious mouse movement.
Replace the open-coded length tracking and pointer arithmetic with
skb pull data() calls. skb pull data() returns NULL if the requested
bytes are not present, eliminating the need for a manual size variable
and the separate skb->len guard.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux