CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's HID subsystem, specifically in the handling of numbered reports within the `hid_get_report` function. An attacker could exploit this flaw by passing a size of 0 to `hid_report_raw_event()`, leading to an out-of-bounds read or potential kernel panic. System administrators and developers managing Linux environments should prioritize applying the fix to mitigate risks associated with this vulnerability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix OOB read in hid_get_report for numbered reports When a caller passes a size of 0 to hid_report_raw_event() for a numbered report, the function originally called hid_get_report() before performing any size validation. Inside hid_get_report(), if the report is numbered (report_enum->numbered is true), it unconditionally dereferences data[0] to extract the report ID. With a size of 0, this results in an out-of-bounds read or kernel panic. Fix this by moving the numbered report size validation check before the call to hid_get_report(), ensuring that size is at least 1 before dereferencing the data pointer.