« Volver al listado

CVE-2026-89999

Estado: RecibidaAlta (8.1)—

In the Linux kernel, the following vulnerability has been resolved:

HID: wacom: validate report length in wacom_intuos_pro2_bt_irq

wacom_intuos_pro2_bt_irq() receives the wire report length in `len` but never consults it before parsing. After the report-id gate it unconditionally calls wacom_intuos_pro2_bt_pen() and then, selected by features.type, a fixed chain of sub-parsers, none of which receive `len`:

Each sub-parser dereferences wacom->data at fixed offsets. The furthest byte touched on each branch is:

features.type is selected from the VID/PID id_table entry and wacom_setup_device_quirks() force-registers the pen/pad/touch inputs for that type independent of the report descriptor, so a malicious or malfunctioning paired/spoofed Bluetooth peripheral can advertise that VID/PID and send an undersized report that still satisfies the data[0] == 0x80/0x81 gate.

Leer descripción completaMostrar menos

The driver then reads past the received report and forwards the bytes to userspace via evdev (MSC_SERIAL / ABS_MISC / ABS_WHEEL on the pen and pad input nodes), an out-of-bounds read with a concrete userspace read-back channel, and a true out-of-bounds read on transports whose backing buffer is sized to the (small) report descriptor rather than a fixed-size staging buffer.

This is the same class of bug commit 2f1763f62909 ("HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq") already hardened in the sibling wacom_intuos_bt_irq(), which guards each report id against its minimum length before parsing.

Guard wacom_intuos_pro2_bt_irq() the same way: before parsing, reject reports shorter than the furthest offset the selected branch actually dereferences, warn, and bail out. Because the whole pen/touch/pad/ battery chain runs unconditionally per branch, a single up-front check against the maximum offset (286 bytes for INTUOSP2_BT/INTUOSP2S_BT, 46 bytes for the gen3 branch) bounds every sub-parser. Returning 0 on a short report also skips those calls for the same malformed report, which is the safe, conservative behavior.

Detalles técnicos trazas, registros y código del informe original
	wacom_intuos_pro2_bt_pen(wacom);
	if (type == INTUOSP2_BT || type == INTUOSP2S_BT) {
		wacom_intuos_pro2_bt_touch(wacom);
		wacom_intuos_pro2_bt_pad(wacom);
		wacom_intuos_pro2_bt_battery(wacom);
	} else {
		wacom_intuos_gen3_bt_pad(wacom);
		wacom_intuos_gen3_bt_battery(wacom);
	}

  INTUOSP2_BT / INTUOSP2S_BT: wacom_intuos_pro2_bt_pad() reads data[285]
	(the touchring byte), so the report must be at least 286 bytes;
  INTUOSHT3_BT ("gen3"): wacom_intuos_gen3_bt_battery() reads data[45],
	so the report must be at least 46 bytes.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad OOB en controlador Wacom Bluetooth (AV:A) explotable por dispositivo periférico malicioso/spoofed. Lectura de memoria no inicializada hacia userspace vía evdev; potencial DoS por corrupción de datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89999",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "d2844f3fcd058113acbe0aa110ab13ef28b98d9f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "1bfc0547b81d5861443420d19b5ed2fd533cd17f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "84781a1f3c5dc6650480be9329e6e8528939eaa0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "96dd0af7597aba2d80cc97e2f66e8b72d30ba125",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "114af803e409a68e52516810ecd24df4d8ce0c68",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "74ec08f7b81c2726578039ca6dea0fec136c38ea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "0cdc6cb242dd8d2731956fdf3390de094482a4b2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b",
              "lessThan": "a8e04f3f894ccb52cfcd7e60125a9f35da4a616d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hid/wacom_wac.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hid/wacom_wac.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:11.177",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0cdc6cb242dd8d2731956fdf3390de094482a4b2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/114af803e409a68e52516810ecd24df4d8ce0c68",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1bfc0547b81d5861443420d19b5ed2fd533cd17f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/74ec08f7b81c2726578039ca6dea0fec136c38ea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84781a1f3c5dc6650480be9329e6e8528939eaa0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/96dd0af7597aba2d80cc97e2f66e8b72d30ba125",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a8e04f3f894ccb52cfcd7e60125a9f35da4a616d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d2844f3fcd058113acbe0aa110ab13ef28b98d9f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: validate report length in wacom_intuos_pro2_bt_irq\n\nwacom_intuos_pro2_bt_irq() receives the wire report length in `len`\nbut never consults it before parsing. After the report-id gate it\nunconditionally calls wacom_intuos_pro2_bt_pen() and then, selected by\nfeatures.type, a fixed chain of sub-parsers, none of which receive\n`len`:\n\n\twacom_intuos_pro2_bt_pen(wacom);\n\tif (type == INTUOSP2_BT || type == INTUOSP2S_BT) {\n\t\twacom_intuos_pro2_bt_touch(wacom);\n\t\twacom_intuos_pro2_bt_pad(wacom);\n\t\twacom_intuos_pro2_bt_battery(wacom);\n\t} else {\n\t\twacom_intuos_gen3_bt_pad(wacom);\n\t\twacom_intuos_gen3_bt_battery(wacom);\n\t}\n\nEach sub-parser dereferences wacom->data at fixed offsets. The furthest\nbyte touched on each branch is:\n\n  INTUOSP2_BT / INTUOSP2S_BT: wacom_intuos_pro2_bt_pad() reads data[285]\n\t(the touchring byte), so the report must be at least 286 bytes;\n  INTUOSHT3_BT (\"gen3\"): wacom_intuos_gen3_bt_battery() reads data[45],\n\tso the report must be at least 46 bytes.\n\nfeatures.type is selected from the VID/PID id_table entry and\nwacom_setup_device_quirks() force-registers the pen/pad/touch inputs\nfor that type independent of the report descriptor, so a malicious or\nmalfunctioning paired/spoofed Bluetooth peripheral can advertise that\nVID/PID and send an undersized report that still satisfies the\ndata[0] == 0x80/0x81 gate. The driver then reads past the received\nreport and forwards the bytes to userspace via evdev (MSC_SERIAL /\nABS_MISC / ABS_WHEEL on the pen and pad input nodes), an out-of-bounds\nread with a concrete userspace read-back channel, and a true\nout-of-bounds read on transports whose backing buffer is sized to the\n(small) report descriptor rather than a fixed-size staging buffer.\n\nThis is the same class of bug commit 2f1763f62909 (\"HID: wacom: fix\nout-of-bounds read in wacom_intuos_bt_irq\") already hardened in the\nsibling wacom_intuos_bt_irq(), which guards each report id against its\nminimum length before parsing.\n\nGuard wacom_intuos_pro2_bt_irq() the same way: before parsing, reject\nreports shorter than the furthest offset the selected branch actually\ndereferences, warn, and bail out. Because the whole pen/touch/pad/\nbattery chain runs unconditionally per branch, a single up-front check\nagainst the maximum offset (286 bytes for INTUOSP2_BT/INTUOSP2S_BT,\n46 bytes for the gen3 branch) bounds every sub-parser. Returning 0 on\na short report also skips those calls for the same malformed report,\nwhich is the safe, conservative behavior."
    }
  ],
  "lastModified": "2026-09-16T15:18:23.543",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}