Executive brief
A vulnerability in the Linux kernel's user-level input (uinput) subsystem could allow a local user to strain system resources. By requesting an extremely large number of input 'slots' (such as those used for multi-touch tracking), an attacker can trigger memory allocation failures and force the system to perform intensive memory reclamation. This can lead to system instability or a denial-of-service condition.
Technical details
A resource exhaustion vulnerability (CWE-770) exists in the Linux kernel's uinput driver. The `uinput_validate_absinfo` function did not previously enforce a maximum limit on the number of multi-touch (MT) slots requested via the `ABS_MT_SLOT` code. A local attacker can exploit this by requesting an 'unreasonable' number of slots, which triggers a memory allocation failure in `input_mt_init_slots()`. While the kernel handles the allocation failure itself, the process of attempting to fulfill the massive request puts undue burden on the system's memory management subsystem, potentially leading to a denial-of-service. The fix introduces a hard limit of 100 slots to ensure allocations remain within reasonable bounds (less than two pages).
Affected products
- Linux Linux Kernel up to 4.19.322, 4.20 to 5.4.284, 5.5 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.110, 6.2 to 6.6.51, 6.7 to 6.10.10, 6.11-rc1 to 6.11-rc4
Timeline
- 2024-08-04: patched: Initial patch authored by Dmitry Torokhov
- 2024-09-18: disclosed: CVE published
References
- https://git.kernel.org/stable/c/206f533a0a7c683982af473079c4111f4a0f9f5e
- https://git.kernel.org/stable/c/51fa08edd80003db700bdaa099385c5900d27f4b
- https://git.kernel.org/stable/c/597ff930296c4c8fc6b6a536884d4f1a7187ec70
- https://git.kernel.org/stable/c/61df76619e270a46fd427fbdeb670ad491c42de2
- https://git.kernel.org/stable/c/9719687398dea8a6a12a10321a54dd75eec7ab2d
- https://git.kernel.org/stable/c/9c6d189f0c1c59ba9a32326ec82a0b367a3cd47b
- https://git.kernel.org/stable/c/a4858b00a1ec57043697fb935565fe267f161833