Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid: fix potential buffer overflow in i2c_hid_get_report()i2c_hid_xfer is used to read recv_len + sizeof(__le16) bytes of data
into ihid->rawbuf.
The former can come from the userspace in the hidraw driver and is only
bounded by HID_MAX_BUFFER_SIZE(16384) by default (unless we also set
max_buffer_size field of struct hid_ll_driver which we do not).
The latter has size determined at runtime by the maximum size of
different report types you could receive on any particular device and
can be a much smaller value.
Fix this by truncating recv_len to ihid->bufsize - sizeof(__le16).
The impact is low since access to hidraw devices requires root.
A potential buffer overflow vulnerability was found in the i2c-hid driver. When handling HID reports via the hidraw interface, userspace can request a recv_len up to HID_MAX_BUFFER_SIZE (16384 bytes), but the destination buffer ihid->rawbuf may be smaller, leading to a heap buffer overflow.
Details
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 12 | Released |
34 kernels
|
| Debian 13 | Planned | — |
| Ubuntu 24.04 | Released |
43 kernels
|
| Ubuntu 24.04 AWS | Planned | — |