Executive brief
A vulnerability in the Linux kernel's Human Interface Device (HID) subsystem could allow a local attacker to access sensitive information. The issue stems from how the system handles data buffers for devices like keyboards and mice. An attacker could potentially use a specially crafted device report to leak fragments of kernel memory, which might contain sensitive system data.
Technical details
A use of uninitialized resource vulnerability (CWE-908) exists in the Linux kernel HID (Human Interface Device) core. The `hid_alloc_report_buf` function in `drivers/hid/hid-core.c` used `kmalloc` to allocate report buffers, which does not zero-initialize the memory. Because these buffers are used by various drivers to process device reports, an attacker with local access could potentially trigger a kernel memory leak by providing a specially-crafted report that reads from the uninitialized portions of the buffer. The fix replaces `kmalloc` with `kzalloc` to ensure the buffer is zero-initialized upon allocation. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Linux Linux Kernel 3.12 to 4.19.324, 4.20 to 5.4.286, 5.5 to 5.10.230, 5.11 to 5.15.172, 5.16 to 6.1.117, 6.2 to 6.6.61, 6.7 to 6.11.8, 6.12-rc1 to 6.12-rc5
Timeline
- 2024-10-29: patched: Initial patch authored by Jiri Kosina
- 2024-11-19: disclosed: CVE published
- 2025-03-04: kev added: Added to CISA Known Exploited Vulnerabilities catalog
References
- https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
- https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552
- https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
- https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
- https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
- https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
- https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46