SB2024071335 - Out-of-bounds read in Linux kernel hid driver
Published: July 13, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2024-40946)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the asus_report_fixup() function in drivers/hid/hid-asus.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/8a630e8acd97c1610f71bb6d864262163410ed6e
- https://git.kernel.org/stable/c/9de62e88310cf50b3ee06344030dc16c19a26ccc
- https://git.kernel.org/stable/c/5c117d5936ca7a271437f3d9eee0fce65edaca2c
- https://git.kernel.org/stable/c/89e1ee118d6f0ee6bd6e80d8fe08839875daa241
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.96
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.36