Impact
The linux kernel’s intel a GET_REPORT request. The driver copies the entire device-supplied report into a caller-provided buffer without verifying the requested length, which is a classic buffer overflow (CWE-120) that can corrupt privileges or cause a denial of service.
Affected Systems
The flaw resides in the Linux kernel intel-quickspi HID driver that interfaces with Intel touch controllers or other HID devices via the quickspi interface. All kernels containing the unpatched driver before the fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8, with an EPSS less than 1 %, suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. It can only be exploited by an attacker who can send malicious HID reports to the device, so the attack surface is limited to users or processes with access to the HID device. If successfully exploited, the kernel buffer overflow could lead to privilege escalation or denial of service. The likely attack vector is local device manipulation, as implied by the need to send a crafted report to the device.
OpenCVE Enrichment