Impact
The Linux kernel HID driver for Wacom Intuos Pro 2 Bluetooth devices does not validate the length of incoming reports before parsing. As a result, an attacker can send an undersized report that still passes initial checks, causing the driver to read past the end of the received data. The leaked bytes are forwarded to userspace via evdev input nodes, providing a channel for the attacker to read arbitrary kernel memory. This represents a confidentiality breach and could be leveraged for further privilege escalation.
Affected Systems
The vulnerability exists in the Linux kernel HID subsystem, affecting all kernel releases that contain the unpatched wacom_intuos_pro2_bt_irq() handler. The fix is included in commits that guard report lengths before parsing; any kernel builds before those commits are vulnerable.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is below 1%, indicating a low to moderate likelihood of exploitation, and the issue is not listed in the National Institute of Standards and Technology CISA Known Exploited Vulnerabilities catalog. The attack vector is user-controlled input via a Bluetooth peripheral; it requires the attacker to pair a malicious or spoofed Bluetooth device or otherwise inject malformed HID reports. Once a suitable device is paired, the driver will blindly read beyond the provided buffer, exposing data to evdev and enabling the attacker to read kernel memory.
OpenCVE Enrichment
Debian DLA
Debian DSA