In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fix…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer struct mms114_touch touch[MMS114_MAX_TOUCH]; which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes, i.e. 80 bytes. The length of the I2C read into it is taken verbatim from the device: packet_size = mms114_read_reg(data, MMS114_PACKET_SIZE); if (packet…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6 Patch
- https://git.kernel.org/stable/c/66725039f7090afe14c31bd259e2059a68f04023 Patch
- https://git.kernel.org/stable/c/8301c335305344d4da4ab9442b6a399dacfe5b8d Patch
- https://git.kernel.org/stable/c/b78150729762d47c14fe29a2582bdca5568e62b8 Patch
- https://git.kernel.org/stable/c/f3d5e77b27fded71dcb97f409262bf0abba0410e Patch
Timeline
- nvd_ingest NVD