Executive brief
A vulnerability in the Linux kernel's Intel Touch Host Controller (THC) driver could allow a local attacker to cause a system crash or potentially gain unauthorized access to sensitive information. The issue occurs when the system processes specific hardware configuration data, leading to a memory error. This could impact the stability and security of devices using Intel QuickI2C interfaces.
Technical details
A stack-based out-of-bounds write (CWE-787) exists in the intel-quicki2c driver within the Intel THC HID subsystem. The vulnerability is caused by the ACPI _DSD methods returning ICRS and ISUB data with a trailing byte that exceeds the defined size of the internal structures `quicki2c_subip_acpi_parameter` and `quicki2c_subip_acpi_config`. When `quicki2c_acpi_get_dsd_property` performs a memory copy, it writes past the end of the stack-allocated buffer. This can be triggered during ACPI resource enumeration, leading to a kernel panic (KASAN detected stack-out-of-bounds). The fix involves adding reserved padding bytes to the affected structures to accommodate the extra data.
Affected products
- Linux Linux Kernel 6.14 to 6.16.5
Timeline
- 2025-08-03: patched: Initial patch authored
- 2025-09-16: disclosed: CVE published