HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts
Published Jul 16, 2024
7.1
HIGHCVSS 3.1
EPSS 0.27%
Description
Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. The root case is in missing validation check of actual number of endpoints.
Code should not blindly access usb_host_interface::endpoint array, since it may contain less endpoints than code expects.
Fix it by adding missing validaion check and print an error if number of endpoints do not match expected number
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.13
- Version 5.15.29StatusunaffectedConstraints<=5.15.*
- Version 5.16.15StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.13 · < 5.15.29
- ≥ 5.16 · < 5.16.15
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
Fixed · RHSA-2024:7001
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10 | Fixed | RHSA-2024:7001 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux version 9.1 and greater include the relevant patch (fc3ef2e3297b) and are therefore unaffected.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-48866 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298640 Issue Tracking
- https://git.kernel.org/stable/c/3ffbe85cda7f523dad896bae08cecd8db8b555ab Patch
- https://git.kernel.org/stable/c/56185434e1e50acecee56d8f5850135009b87947 Patch
- https://git.kernel.org/stable/c/fc3ef2e3297b3c0e2006b5d7b3d66965e3392036 Patch
- https://lore.kernel.org/linux-cve-announce/2024071629-CVE-2022-48866-93bd@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48866
- https://www.cve.org/CVERecord?id=CVE-2022-48866
Change history (0)
No recorded changes yet.