PT-2026-61264 · Linux · Linux

CVE-2026-63947

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: fix missing length checks in hidp input report()
hidp input report() reads keyboard and mouse payload data from an skb without first verifying that skb->len contains enough data.
hidp recv intr frame() pulls the 1-byte HIDP header before dispatching to hidp input report(). If a paired device sends a truncated packet, the handler reads beyond the valid skb data, resulting in an out-of-bounds read of skb data. The OOB bytes may be interpreted as phantom key presses or spurious mouse movement.
Replace the open-coded length tracking and pointer arithmetic with skb pull data() calls. skb pull data() returns NULL if the requested bytes are not present, eliminating the need for a manual size variable and the separate skb->len guard.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63947

Affected Products

Linux