Executive brief
A vulnerability in the Linux kernel's Human Interface Device (HID) driver could allow a malicious or malfunctioning USB/Bluetooth device to crash the system. By providing a specially crafted device descriptor, the device can trigger an internal error that leads to a system hang or crash. This affects the reliability and availability of systems where untrusted hardware can be connected.
Technical details
A shift-out-of-bounds vulnerability exists in the Linux kernel HID core within the s32ton() function. The function performs a bit-shift by n-1, where n is the report_size provided by the HID device. Because the HID parser only bounds report_size to <= 256, a malicious device can provide a value that exceeds the 32-bit width of the target type, triggering undefined behavior. This occurs during the construction of output reports via hid_output_field() or hid_set_field(). The fix involves clamping the report_size (n) to a maximum of 32 bits, consistent with existing fixes in related functions like snto32().
Affected products
- Linux Linux Kernel versions from 2.6.20.1 up to 6.6.136, 6.7 up to 6.12.83, 6.13 up to 6.18.24, 6.19 up to 6.19.14, 7.0 up to 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-04-13: patched: Initial patch in mainline kernel tree
References
- https://git.kernel.org/stable/c/0ab048dbdb1daacf17d52e9252297eb6e1298e49
- https://git.kernel.org/stable/c/58386f00af710922cafb0fb69211497beddfaa95
- https://git.kernel.org/stable/c/69c02ffde6ed4d535fa4e693a9e572729cad3d0d
- https://git.kernel.org/stable/c/76ad02854a30c394e0c076e6e6bed0a388573a94
- https://git.kernel.org/stable/c/8a8333237f1f5caab8d4c3d2c2e7578c4263a97f
- https://git.kernel.org/stable/c/932ae5309e53561197aa7d1606c7cf63af10e24f
- https://git.kernel.org/stable/c/97014719bb8fccb1ffcbbc299e84b1f11b114195