Junglewise Threat Intelligence

CVE-2026-31624: Linux Kernel undefined shift in HID core s32ton

CVE-2026-31624 · Severity: medium · CVSS 5.5 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Human Interface Device (HID) driver could allow a malicious or malfunctioning USB/Bluetooth device to crash the system. By providing a specially crafted device descriptor, the device can trigger an internal error that leads to a system hang or crash. This affects the reliability and availability of systems where untrusted hardware can be connected.

Technical details

A shift-out-of-bounds vulnerability exists in the Linux kernel HID core within the s32ton() function. The function performs a bit-shift by n-1, where n is the report_size provided by the HID device. Because the HID parser only bounds report_size to <= 256, a malicious device can provide a value that exceeds the 32-bit width of the target type, triggering undefined behavior. This occurs during the construction of output reports via hid_output_field() or hid_set_field(). The fix involves clamping the report_size (n) to a maximum of 32 bits, consistent with existing fixes in related functions like snto32().

Affected products

  • Linux Linux Kernel versions from 2.6.20.1 up to 6.6.136, 6.7 up to 6.12.83, 6.13 up to 6.18.24, 6.19 up to 6.19.14, 7.0 up to 7.0.1

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory
  • 2026-04-13: patched: Initial patch in mainline kernel tree

References

Related threats