Executive brief
A vulnerability in the Linux kernel's N-Trig touch screen driver could allow a local user to crash the system. By sending specific data to the system's user-space HID interface, an attacker can trigger a memory error (page fault) that leads to a kernel panic. This results in a complete denial of service, requiring a system reboot to restore operations.
Technical details
A NULL pointer dereference vulnerability exists in the ntrig_report_version() function within the HID N-Trig driver (drivers/hid/hid-ntrig.c). The issue occurs when a descriptor is sent to /dev/uhid, which can cause the device's parent pointers to be NULL. When hid_to_usb_dev() is subsequently called, it returns an invalid address that triggers a page fault when used by usb_rcvctrlpipe(). A local attacker with access to the HID interface can exploit this to cause a kernel oops or panic. The fix introduces a check using hid_is_usb() to ensure the device is a valid USB device before proceeding with USB-specific operations.
Affected products
- Linux Linux Kernel 2.6.37 to 5.4.298, 5.5 to 5.10.242, 5.11 to 5.15.191, 5.16 to 6.1.150, 6.2 to 6.6.104, 6.7 to 6.12.45, 6.13 to 6.16.5
Timeline
- 2025-08-13: patched: Initial patch submitted by Samsung developers
- 2025-09-16: disclosed: CVE published and added to kernel stable trees
References
- https://git.kernel.org/stable/c/019c34ca11372de891c06644846eb41fca7c890c
- https://git.kernel.org/stable/c/183def8e4d786e50165e5d992df6a3083e45e16c
- https://git.kernel.org/stable/c/185c926283da67a72df20a63a5046b3b4631b7d9
- https://git.kernel.org/stable/c/22ddb5eca4af5e69dffe2b54551d2487424448f1
- https://git.kernel.org/stable/c/4338b0f6544c3ff042bfbaf40bc9afe531fb08c7
- https://git.kernel.org/stable/c/6070123d5344d0950f10ef6a5fdc3f076abb7ad2
- https://git.kernel.org/stable/c/98520a9a3d69a530dd1ee280cbe0abc232a35bff