CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's synaptics-rmi4 driver, where an improper handling of the GPIO/LED count can lead to out-of-bounds reads and writes. This flaw allows devices reporting a GPIO count greater than six to exploit memory access issues, potentially leading to arbitrary code execution or system crashes. Organizations using affected Linux systems, particularly those with devices utilizing GPIO support, should prioritize patching this vulnerability to mitigate the risk of exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f30_attention() iterates the full f30->gpioled_count (device query register, range 0..31) and dereferences gpioled_key_map[i], and input->keycodemax is set to the full gpioled_count while input->keycode points at the 6-entry allocation. A device that reports gpioled_count > 6 with GPIO support enabled therefore causes an out-of-bounds read on the attention interrupt and out-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls, which bound the index only against keycodemax. This is the same defect as the F3A handler, which was copied from F30. Size the keymap for the full gpioled_count; the mapping loop still assigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries.
Related CVEs
Other vulnerabilities affecting the same vendor(s)