Impact
A malicious USB HID device claiming the Roccat Kone identifier can supply an 8‑bit profile index that exceeds the 5‑element array maintained by the driver. The driver uses the value as an array index in two code paths without a bounds check, causing an out‑of‑bounds read. The data read is exposed through the actual_dpi sysfs attribute, allowing an attacker to learn DPI settings for the mouse and potentially other internal state. This vulnerability is an out‑of‑bounds read that can leak sensitive information.
Affected Systems
The flaw exists in the Linux kernel’s Roccat HID driver for the Kone mouse and affects all kernel releases that include the unpatched driver. No specific version range is listed, so all kernels prior to the patch are potentially impacted.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability that it will be actively exploited. The attack requires a physical USB device that can emulate a Roccat Kone and requires the device to be connected to a Linux system. Although the exploitation can read data from a sysfs file, the overall risk is modest until a patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA