8.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Adjacent (A)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Adjacent (A)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (max. allowed matches exceeded) suggestion
Bluetooth: HIDP: fix missing length checks in hidp_input_report()
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: fix missing length checks in hidp_input_report() hidp_input_report() reads keyboard and mouse payload data from an skb without first verifying that skb->len contains enough data. hidp_recv_intr_frame() pulls the 1-byte HIDP header before dispatching to hidp_input_report(). If a paired device sends a truncated packet, the handler reads beyond the valid skb data, resulting in an out-of-bounds read of skb data. The OOB bytes may be interpreted as phantom key presses or spurious mouse movement. Replace the open-coded length tracking and pointer arithmetic with skb_pull_data() calls. skb_pull_data() returns NULL if the requested bytes are not present, eliminating the need for a manual size variable and the separate skb->len guard.
References
Affected products
- <d313683d6ccdd8c01e0562270a2ae25b86d8461d
- <cc3832b19f863e3677c5651f001a2e3795f39eb8
- <1f08a90013e1e632b34321334e861fcefc056505
- <2a3ac9ee11dbb9845f3947cef4a79dba658cf6f6
- =<6.18.*
- =<7.0.*
- =<6.12.*
- <2.6.12
- =<6.1.*
- =<*
- <6348dfed5b0f9c6074f14322332e97493d32fef0
- ==2.6.12
- <d7d6a81b8dd1a8d084a1b755db9406041d53adb5
- =<5.15.*
- =<6.6.*
- <b83dcacd2ec7fcc5a48be215f82d573759f87ec2