CVE-2025-39806 (GCVE-0-2025-39806)
Vulnerability from cvelistv5
Published
2025-09-16 13:00
Modified
2026-08-05 12:05
Summary
In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() A malicious HID device can trigger a slab out-of-bounds during mt_report_fixup() by passing in report descriptor smaller than 607 bytes. mt_report_fixup() attempts to patch byte offset 607 of the descriptor with 0x25 by first checking if byte offset 607 is 0x15 however it lacks bounds checks to verify if the descriptor is big enough before conducting this check. Fix this bug by ensuring the descriptor size is at least 608 bytes before accessing it. Below is the KASAN splat after the out of bounds access happens: [ 13.671954] ================================================================== [ 13.672667] BUG: KASAN: slab-out-of-bounds in mt_report_fixup+0x103/0x110 [ 13.673297] Read of size 1 at addr ffff888103df39df by task kworker/0:1/10 [ 13.673297] [ 13.673297] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Not tainted 6.15.0-00005-gec5d573d83f4-dirty #3 [ 13.673297] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/04 [ 13.673297] Call Trace: [ 13.673297] <TASK> [ 13.673297] dump_stack_lvl+0x5f/0x80 [ 13.673297] print_report+0xd1/0x660 [ 13.673297] kasan_report+0xe5/0x120 [ 13.673297] __asan_report_load1_noabort+0x18/0x20 [ 13.673297] mt_report_fixup+0x103/0x110 [ 13.673297] hid_open_report+0x1ef/0x810 [ 13.673297] mt_probe+0x422/0x960 [ 13.673297] hid_device_probe+0x2e2/0x6f0 [ 13.673297] really_probe+0x1c6/0x6b0 [ 13.673297] __driver_probe_device+0x24f/0x310 [ 13.673297] driver_probe_device+0x4e/0x220 [ 13.673297] __device_attach_driver+0x169/0x320 [ 13.673297] bus_for_each_drv+0x11d/0x1b0 [ 13.673297] __device_attach+0x1b8/0x3e0 [ 13.673297] device_initial_probe+0x12/0x20 [ 13.673297] bus_probe_device+0x13d/0x180 [ 13.673297] device_add+0xe3a/0x1670 [ 13.673297] hid_add_device+0x31d/0xa40 [...]
Impacted products
Vendor Product Version
Linux Linux Version: 7d91a0b2151a9c3b61d44c85c8eba930eddd1dd0
Version: 45ec9f17ce46417fc4eccecf388c99e81fb7fcc1
Version: 1d5c7d0a49ec9d8786f266ac6d1d7c4960e1787b
Version: c8000deb68365b461b324d68c7ea89d730f0bb85
Version: c8000deb68365b461b324d68c7ea89d730f0bb85
Version: c8000deb68365b461b324d68c7ea89d730f0bb85
Version: d189e24a42b8bd0ece3d28801d751bf66dba8e92
Version: 5.15.168   
Version: 6.1.111   
Version: 6.6.52   
Version: 6.10.11   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T17:43:32.753Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC CN 4100",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V5.0",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T12:07:11.286Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          }
        ],
        "x_adpType": "supplier"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-39806",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-10T20:41:42.602862Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-11T18:44:15.347Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/hid/hid-multitouch.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4263e5851779f7d8ebfbc9cc7d2e9b0217adba8d",
              "status": "affected",
              "version": "7d91a0b2151a9c3b61d44c85c8eba930eddd1dd0",
              "versionType": "git"
            },
            {
              "lessThan": "7ab7311c43ae19c66c53ccd8c5052a9072a4e338",
              "status": "affected",
              "version": "45ec9f17ce46417fc4eccecf388c99e81fb7fcc1",
              "versionType": "git"
            },
            {
              "lessThan": "d4e6e2680807671e1c73cd6a986b33659ce92f2b",
              "status": "affected",
              "version": "1d5c7d0a49ec9d8786f266ac6d1d7c4960e1787b",
              "versionType": "git"
            },
            {
              "lessThan": "3055309821dd3da92888f88bad10f0324c3c89fe",
              "status": "affected",
              "version": "c8000deb68365b461b324d68c7ea89d730f0bb85",
              "versionType": "git"
            },
            {
              "lessThan": "c13e95587583d018cfbcc277df7e02d41902ac5a",
              "status": "affected",
              "version": "c8000deb68365b461b324d68c7ea89d730f0bb85",
              "versionType": "git"
            },
            {
              "lessThan": "0379eb8691b9c4477da0277ae0832036ca4410b4",
              "status": "affected",
              "version": "c8000deb68365b461b324d68c7ea89d730f0bb85",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d189e24a42b8bd0ece3d28801d751bf66dba8e92",
              "versionType": "git"
            },
            {
              "lessThan": "5.15.191",
              "status": "affected",
              "version": "5.15.168",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1.150",
              "status": "affected",
              "version": "6.1.111",
              "versionType": "semver"
            },
            {
              "lessThan": "6.6.104",
              "status": "affected",
              "version": "6.6.52",
              "versionType": "semver"
            },
            {
              "lessThan": "6.11",
              "status": "affected",
              "version": "6.10.11",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/hid/hid-multitouch.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "lessThan": "6.11",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.191",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.150",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.104",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.45",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.16.*",
              "status": "unaffected",
              "version": "6.16.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.191",
                  "versionStartIncluding": "5.15.168",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.150",
                  "versionStartIncluding": "6.1.111",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.104",
                  "versionStartIncluding": "6.6.52",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.45",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16.5",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.10.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: fix slab out-of-bounds access in mt_report_fixup()\n\nA malicious HID device can trigger a slab out-of-bounds during\nmt_report_fixup() by passing in report descriptor smaller than\n607 bytes. mt_report_fixup() attempts to patch byte offset 607\nof the descriptor with 0x25 by first checking if byte offset\n607 is 0x15 however it lacks bounds checks to verify if the\ndescriptor is big enough before conducting this check. Fix\nthis bug by ensuring the descriptor size is at least 608\nbytes before accessing it.\n\nBelow is the KASAN splat after the out of bounds access happens:\n\n[   13.671954] ==================================================================\n[   13.672667] BUG: KASAN: slab-out-of-bounds in mt_report_fixup+0x103/0x110\n[   13.673297] Read of size 1 at addr ffff888103df39df by task kworker/0:1/10\n[   13.673297]\n[   13.673297] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Not tainted 6.15.0-00005-gec5d573d83f4-dirty #3\n[   13.673297] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/04\n[   13.673297] Call Trace:\n[   13.673297]  \u003cTASK\u003e\n[   13.673297]  dump_stack_lvl+0x5f/0x80\n[   13.673297]  print_report+0xd1/0x660\n[   13.673297]  kasan_report+0xe5/0x120\n[   13.673297]  __asan_report_load1_noabort+0x18/0x20\n[   13.673297]  mt_report_fixup+0x103/0x110\n[   13.673297]  hid_open_report+0x1ef/0x810\n[   13.673297]  mt_probe+0x422/0x960\n[   13.673297]  hid_device_probe+0x2e2/0x6f0\n[   13.673297]  really_probe+0x1c6/0x6b0\n[   13.673297]  __driver_probe_device+0x24f/0x310\n[   13.673297]  driver_probe_device+0x4e/0x220\n[   13.673297]  __device_attach_driver+0x169/0x320\n[   13.673297]  bus_for_each_drv+0x11d/0x1b0\n[   13.673297]  __device_attach+0x1b8/0x3e0\n[   13.673297]  device_initial_probe+0x12/0x20\n[   13.673297]  bus_probe_device+0x13d/0x180\n[   13.673297]  device_add+0xe3a/0x1670\n[   13.673297]  hid_add_device+0x31d/0xa40\n[...]"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - hid-multitouch binds on HID_BUS_ANY, and for Bluetooth HID the vendor/product IDs and the entire report descriptor come from the remote peer via hidp_connadd_req (net/bluetooth/hidp/core.c:773-791), so an attacker within Bluetooth range can present VID 0x27c6/PID 0x01e8 with a short descriptor; a malicious USB device reaches the identical path.\nAC:L - The attacker fully controls both trigger conditions \u2014 the vendor/product IDs and the descriptor length \u2014 so a descriptor under 608 bytes deterministically drives the out-of-bounds access on every probe, with no race or unknown state involved.\nPR:N - The fault occurs in mt_probe()/hid_open_report() during device enumeration, before any userspace interaction with the device, so the attacker needs no account or privileges on the target system.\nUI:N - Driver probe and report-descriptor fixup run automatically when the HID transport connects, with no victim action required beyond the device being attached or connected.\nS:U - The out-of-bounds read and write stay within the kernel\u0027s own slab memory and the kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The read at rdesc[607] reaches into an adjacent slab object whose bucket the attacker selects via the descriptor size, and the else-branch prints that out-of-bounds byte to the kernel log (\"got: %x\"), giving a repeatable, attacker-positioned heap disclosure primitive.\nI:H - When the out-of-bounds byte reads as 0x15 the code writes 0x25 back to it, producing a genuine slab out-of-bounds write into a neighbouring, heap-groomable object that can corrupt adjacent kernel structures.\nA:H - The out-of-bounds access triggers a KASAN BUG (panic with panic_on_warn), can fault on an unmapped page under KFENCE or small allocations, and the stray write can corrupt adjacent objects into a later kernel crash."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:05:19.463Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4263e5851779f7d8ebfbc9cc7d2e9b0217adba8d"
        },
        {
          "url": "https://git.kernel.org/stable/c/7ab7311c43ae19c66c53ccd8c5052a9072a4e338"
        },
        {
          "url": "https://git.kernel.org/stable/c/d4e6e2680807671e1c73cd6a986b33659ce92f2b"
        },
        {
          "url": "https://git.kernel.org/stable/c/3055309821dd3da92888f88bad10f0324c3c89fe"
        },
        {
          "url": "https://git.kernel.org/stable/c/c13e95587583d018cfbcc277df7e02d41902ac5a"
        },
        {
          "url": "https://git.kernel.org/stable/c/0379eb8691b9c4477da0277ae0832036ca4410b4"
        }
      ],
      "title": "HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-39806",
    "datePublished": "2025-09-16T13:00:09.524Z",
    "dateReserved": "2025-04-16T07:20:57.136Z",
    "dateUpdated": "2026-08-05T12:05:19.463Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T17:43:32.753Z\"}}, {\"affected\": [{\"vendor\": \"Siemens\", \"product\": \"SIMATIC CN 4100\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"V5.0\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unknown\"}], \"x_adpType\": \"supplier\", \"references\": [{\"url\": \"https://cert-portal.siemens.com/productcert/html/ssa-032379.html\"}], \"providerMetadata\": {\"orgId\": \"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e\", \"shortName\": \"siemens-SADP\", \"dateUpdated\": \"2026-05-12T12:07:11.286Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-39806\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-06-10T20:41:42.602862Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-06-11T17:38:38.928Z\"}}], \"cna\": {\"title\": \"HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 8.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:A - hid-multitouch binds on HID_BUS_ANY, and for Bluetooth HID the vendor/product IDs and the entire report descriptor come from the remote peer via hidp_connadd_req (net/bluetooth/hidp/core.c:773-791), so an attacker within Bluetooth range can present VID 0x27c6/PID 0x01e8 with a short descriptor; a malicious USB device reaches the identical path.\\nAC:L - The attacker fully controls both trigger conditions \\u2014 the vendor/product IDs and the descriptor length \\u2014 so a descriptor under 608 bytes deterministically drives the out-of-bounds access on every probe, with no race or unknown state involved.\\nPR:N - The fault occurs in mt_probe()/hid_open_report() during device enumeration, before any userspace interaction with the device, so the attacker needs no account or privileges on the target system.\\nUI:N - Driver probe and report-descriptor fixup run automatically when the HID transport connects, with no victim action required beyond the device being attached or connected.\\nS:U - The out-of-bounds read and write stay within the kernel\u0027s own slab memory and the kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The read at rdesc[607] reaches into an adjacent slab object whose bucket the attacker selects via the descriptor size, and the else-branch prints that out-of-bounds byte to the kernel log (\\\"got: %x\\\"), giving a repeatable, attacker-positioned heap disclosure primitive.\\nI:H - When the out-of-bounds byte reads as 0x15 the code writes 0x25 back to it, producing a genuine slab out-of-bounds write into a neighbouring, heap-groomable object that can corrupt adjacent kernel structures.\\nA:H - The out-of-bounds access triggers a KASAN BUG (panic with panic_on_warn), can fault on an unmapped page under KFENCE or small allocations, and the stray write can corrupt adjacent objects into a later kernel crash.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"7d91a0b2151a9c3b61d44c85c8eba930eddd1dd0\", \"lessThan\": \"4263e5851779f7d8ebfbc9cc7d2e9b0217adba8d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"45ec9f17ce46417fc4eccecf388c99e81fb7fcc1\", \"lessThan\": \"7ab7311c43ae19c66c53ccd8c5052a9072a4e338\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1d5c7d0a49ec9d8786f266ac6d1d7c4960e1787b\", \"lessThan\": \"d4e6e2680807671e1c73cd6a986b33659ce92f2b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c8000deb68365b461b324d68c7ea89d730f0bb85\", \"lessThan\": \"3055309821dd3da92888f88bad10f0324c3c89fe\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c8000deb68365b461b324d68c7ea89d730f0bb85\", \"lessThan\": \"c13e95587583d018cfbcc277df7e02d41902ac5a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c8000deb68365b461b324d68c7ea89d730f0bb85\", \"lessThan\": \"0379eb8691b9c4477da0277ae0832036ca4410b4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d189e24a42b8bd0ece3d28801d751bf66dba8e92\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5.15.168\", \"lessThan\": \"5.15.191\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.1.111\", \"lessThan\": \"6.1.150\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.6.52\", \"lessThan\": \"6.6.104\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.10.11\", \"lessThan\": \"6.11\", \"versionType\": \"semver\"}], \"programFiles\": [\"drivers/hid/hid-multitouch.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.11\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.11\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.191\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.150\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.104\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.45\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.16.5\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.16.*\"}, {\"status\": \"unaffected\", \"version\": \"6.17\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/hid/hid-multitouch.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/4263e5851779f7d8ebfbc9cc7d2e9b0217adba8d\"}, {\"url\": \"https://git.kernel.org/stable/c/7ab7311c43ae19c66c53ccd8c5052a9072a4e338\"}, {\"url\": \"https://git.kernel.org/stable/c/d4e6e2680807671e1c73cd6a986b33659ce92f2b\"}, {\"url\": \"https://git.kernel.org/stable/c/3055309821dd3da92888f88bad10f0324c3c89fe\"}, {\"url\": \"https://git.kernel.org/stable/c/c13e95587583d018cfbcc277df7e02d41902ac5a\"}, {\"url\": \"https://git.kernel.org/stable/c/0379eb8691b9c4477da0277ae0832036ca4410b4\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nHID: multitouch: fix slab out-of-bounds access in mt_report_fixup()\\n\\nA malicious HID device can trigger a slab out-of-bounds during\\nmt_report_fixup() by passing in report descriptor smaller than\\n607 bytes. mt_report_fixup() attempts to patch byte offset 607\\nof the descriptor with 0x25 by first checking if byte offset\\n607 is 0x15 however it lacks bounds checks to verify if the\\ndescriptor is big enough before conducting this check. Fix\\nthis bug by ensuring the descriptor size is at least 608\\nbytes before accessing it.\\n\\nBelow is the KASAN splat after the out of bounds access happens:\\n\\n[   13.671954] ==================================================================\\n[   13.672667] BUG: KASAN: slab-out-of-bounds in mt_report_fixup+0x103/0x110\\n[   13.673297] Read of size 1 at addr ffff888103df39df by task kworker/0:1/10\\n[   13.673297]\\n[   13.673297] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Not tainted 6.15.0-00005-gec5d573d83f4-dirty #3\\n[   13.673297] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/04\\n[   13.673297] Call Trace:\\n[   13.673297]  \u003cTASK\u003e\\n[   13.673297]  dump_stack_lvl+0x5f/0x80\\n[   13.673297]  print_report+0xd1/0x660\\n[   13.673297]  kasan_report+0xe5/0x120\\n[   13.673297]  __asan_report_load1_noabort+0x18/0x20\\n[   13.673297]  mt_report_fixup+0x103/0x110\\n[   13.673297]  hid_open_report+0x1ef/0x810\\n[   13.673297]  mt_probe+0x422/0x960\\n[   13.673297]  hid_device_probe+0x2e2/0x6f0\\n[   13.673297]  really_probe+0x1c6/0x6b0\\n[   13.673297]  __driver_probe_device+0x24f/0x310\\n[   13.673297]  driver_probe_device+0x4e/0x220\\n[   13.673297]  __device_attach_driver+0x169/0x320\\n[   13.673297]  bus_for_each_drv+0x11d/0x1b0\\n[   13.673297]  __device_attach+0x1b8/0x3e0\\n[   13.673297]  device_initial_probe+0x12/0x20\\n[   13.673297]  bus_probe_device+0x13d/0x180\\n[   13.673297]  device_add+0xe3a/0x1670\\n[   13.673297]  hid_add_device+0x31d/0xa40\\n[...]\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.191\", \"versionStartIncluding\": \"5.15.168\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.150\", \"versionStartIncluding\": \"6.1.111\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.104\", \"versionStartIncluding\": \"6.6.52\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.45\", \"versionStartIncluding\": \"6.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.16.5\", \"versionStartIncluding\": \"6.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.17\", \"versionStartIncluding\": \"6.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"6.10.11\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T12:05:19.463Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-39806\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T12:05:19.463Z\", \"dateReserved\": \"2025-04-16T07:20:57.136Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-09-16T13:00:09.524Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…