PT-2026-61264 · Linux · Linux

CVE-2026-63947

·

Publicado

2026-07-19

·

Atualizado

2026-07-19

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: fix missing length checks in hidp input report()
hidp input report() reads keyboard and mouse payload data from an skb without first verifying that skb->len contains enough data.
hidp recv intr frame() pulls the 1-byte HIDP header before dispatching to hidp input report(). If a paired device sends a truncated packet, the handler reads beyond the valid skb data, resulting in an out-of-bounds read of skb data. The OOB bytes may be interpreted as phantom key presses or spurious mouse movement.
Replace the open-coded length tracking and pointer arithmetic with skb pull data() calls. skb pull data() returns NULL if the requested bytes are not present, eliminating the need for a manual size variable and the separate skb->len guard.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-63947

Produtos afetados

Linux