CVE-2026-63916 (GCVE-0-2026-63916)
Vulnerability from cvelistv5
Published
2026-07-19 14:55
Modified
2026-08-05 12:37
Summary
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: Fix OOB write in wacom_hid_set_device_mode() wacom_hid_set_device_mode() currently assumes that the HID_DG_INPUTMODE usage is always located in the first field (field[0]) of the feature report. However, a device can specify HID_DG_INPUTMODE in a different field. If HID_DG_INPUTMODE is in a field other than the first one and the first field has a report_count smaller than the usage_index of HID_DG_INPUTMODE, this leads to an out-of-bounds write to r->field[0]->value. Fix this by storing the field index of HID_DG_INPUTMODE in 'struct hid_data' during feature mapping. In wacom_hid_set_device_mode(), use this stored field index to access the correct field and add bounds checks to ensure both the field index and the value index are within valid ranges before writing.
Impacted products
Vendor Product Version
Linux Linux Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Version: 5ae6e89f7409cb5d218bb728326eba9c650d9700
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/hid/wacom_sys.c",
            "drivers/hid/wacom_wac.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "2add311d99646c9d235b2c44f9c169ba30f5db3a",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            },
            {
              "lessThan": "83bd8a5756a3c4a413ed8f6253f9eb2821e1ccaf",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            },
            {
              "lessThan": "5716a293fb19d382ca2336e08fd28a619a5f3c25",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            },
            {
              "lessThan": "ed598de9f61582902406d352d99f2073d8e00298",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            },
            {
              "lessThan": "43e7c02d6090a82fd60d63491f6871aec906345e",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            },
            {
              "lessThan": "b8338111e14183972359009c12d0dbd81d2e1e16",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            },
            {
              "lessThan": "5db3fca0cec7b33bc5379411d0a60d792c9f9bc0",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            },
            {
              "lessThan": "c0a8899e02ddebd51e2589835182c239c2e224ae",
              "status": "affected",
              "version": "5ae6e89f7409cb5d218bb728326eba9c650d9700",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/hid/wacom_sys.c",
            "drivers/hid/wacom_wac.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.18"
            },
            {
              "lessThan": "3.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.93",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.35",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.259",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.210",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.176",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.143",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.93",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.35",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.12",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: Fix OOB write in wacom_hid_set_device_mode()\n\nwacom_hid_set_device_mode() currently assumes that the HID_DG_INPUTMODE\nusage is always located in the first field (field[0]) of the feature report.\nHowever, a device can specify HID_DG_INPUTMODE in a different field.\n\nIf HID_DG_INPUTMODE is in a field other than the first one and the first\nfield has a report_count smaller than the usage_index of HID_DG_INPUTMODE,\nthis leads to an out-of-bounds write to r-\u003efield[0]-\u003evalue.\n\nFix this by storing the field index of HID_DG_INPUTMODE in \u0027struct\nhid_data\u0027 during feature mapping.  In wacom_hid_set_device_mode(), use\nthis stored field index to access the correct field and add bounds\nchecks to ensure both the field index and the value index are within\nvalid ranges before writing."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - The bug is triggered when the kernel probes a Wacom HID device whose report descriptor is supplied by the peripheral; Bluetooth Wacom tablets are widely deployed and an attacker within radio range can present a malicious spoofed Wacom Bluetooth HID device, which is a more severe but reasonable reach path than USB-only scenarios.\nAC:L - The attacker fully controls the malicious device\u0027s HID report descriptor and can reliably place HID_DG_INPUTMODE in a non-first field with a high usage_index while keeping field[0]\u0027s report_count small, causing deterministic OOB write during driver initialization without race conditions or rare configuration.\nPR:N - Exploitation requires no privileges on the victim system; an attacker only needs to connect or spoof a malicious Wacom HID peripheral (USB plug-in or Bluetooth advertisement), with no login, capabilities, or user-namespace access required on the target host.\nUI:N - No victim interaction with applications or files is needed; the attacker can physically connect a USB device to an unattended machine or deliver a spoofed Bluetooth peripheral, and the kernel automatically parses the descriptor and calls the vulnerable function during device probe or resume.\nS:U - The out-of-bounds write corrupts kernel heap memory within the same kernel security boundary, enabling local privilege escalation or denial of service but not crossing a VM, IOMMU, or sandbox boundary.\nC:H - The out-of-bounds write to field[0]-\u003evalue can corrupt adjacent heap objects (new_value, usages_priorities, or neighboring kmalloc allocations), and such kernel heap memory corruption is reasonably exploitable for information disclosure.\nI:H - This is an out-of-bounds write in kernel heap memory with attacker-influenced offset and value (writes integer 2), which per CVSS kernel guidance constitutes high integrity impact due to potential arbitrary memory corruption and code execution.\nA:H - Corrupting kernel heap metadata or adjacent objects during device initialization can cause kernel oops, panic, or hang, and any out-of-bounds write in kernel space carries high availability impact even before full exploitation."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:37:10.495Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2add311d99646c9d235b2c44f9c169ba30f5db3a"
        },
        {
          "url": "https://git.kernel.org/stable/c/83bd8a5756a3c4a413ed8f6253f9eb2821e1ccaf"
        },
        {
          "url": "https://git.kernel.org/stable/c/5716a293fb19d382ca2336e08fd28a619a5f3c25"
        },
        {
          "url": "https://git.kernel.org/stable/c/ed598de9f61582902406d352d99f2073d8e00298"
        },
        {
          "url": "https://git.kernel.org/stable/c/43e7c02d6090a82fd60d63491f6871aec906345e"
        },
        {
          "url": "https://git.kernel.org/stable/c/b8338111e14183972359009c12d0dbd81d2e1e16"
        },
        {
          "url": "https://git.kernel.org/stable/c/5db3fca0cec7b33bc5379411d0a60d792c9f9bc0"
        },
        {
          "url": "https://git.kernel.org/stable/c/c0a8899e02ddebd51e2589835182c239c2e224ae"
        }
      ],
      "title": "HID: wacom: Fix OOB write in wacom_hid_set_device_mode()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-63916",
    "datePublished": "2026-07-19T14:55:20.015Z",
    "dateReserved": "2026-07-19T07:54:57.020Z",
    "dateUpdated": "2026-08-05T12:37:10.495Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…