Impact
The vulnerability exists in the HID sensor‑hub driver of the Linux kernel. The function sensor_hub_get_feature copies a fixed number of bytes for each report value regardless of the size of the caller’s buffer. A malicious HID descriptor can advertise a large feature field size while the caller supplies a small stack buffer, resulting in an out‑of‑bounds write that can corrupt adjacent stack data. This buffer overflow to memory corruption in kernel space and potentially crash the system or cause unpredictable behavior.
Affected Systems
All Linux kernel builds containing the HID sensor‑hub driver are affected. The CVE description does not specify exact kernel versions, but any kernel in which sensor_hub_get_feature is present and the fix is not applied is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The EPSS score is under 1 %, indicating the likelihood of exploitation is very low. The flaw is not listed in CISA's KEV catalog. The most likely attack vector is a malicious HID descriptor supplied by an external USB host. Successful exploitation could corrupt kernel memory and potentially crash the system or provide an attacker with a foothold for further escalation.
OpenCVE Enrichment
Debian DSA