CVE-2026-89999
CVE CVE-2026-89999EUVD EUVD-2026-80607Veröffentlicht 2026-09-16T10:33:10.000ZZuletzt geändert 2026-09-16T14:41:14.000ZCVSS 8.1
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: validate report length in wacom_intuos_pro2_bt_irq wacom_intuos_pro2_bt_irq() receives the wire report length in `len` but never consults it before parsing. After the report-id gate it unconditionally calls wacom_intuos_pro2_bt_pen() and then, selected by features.type, a fixed chain of sub-parsers, none of which receive `len`: wacom_intuos_pro2_bt_pen(wacom); if (type == INTUOSP2_BT || type == INTUOSP2S_BT) { wacom_intuos_pro2_bt_touch(wacom); wacom_intuos_pro2_bt_pad(wacom); wacom_intuos_pro2_bt_battery(wacom); } else { wacom_intuos_gen3_bt_pad(wacom); wacom_intuos_gen3_bt_battery(wacom); } Each sub-parser dereferences wacom->data at fixed offsets. The furthest byte touched on each branch is: INTUOSP2_BT / INTUOSP2S_BT: wacom_intuos_pro2_bt_pad() reads data[285] (the touchring byte), so the report must be at least 286 bytes; INTUOSHT3_BT ("gen3"): wacom_intuos_gen3_bt_battery() reads data[45], so the report must be at least 46 bytes. features.type is selected from the VID/PID id_table entry and wacom_setup_device_quirks() force-registers the pen/pad/touch inputs for that type independent of the report descriptor, so a malicious or malfunctioning paired/spoofed Bluetooth peripheral can advertise that VID/PID and send an undersized report that still satisfies the data[0] == 0x80/0x81 gate. The driver then reads past the received report and forwards the bytes to userspace via evdev (MSC_SERIAL / ABS_MISC / ABS_WHEEL on the pen and pad input nodes), an out-of-bounds read with a concrete userspace read-back channel, and a true out-of-bounds read on transports whose backing buffer is sized to the (small) report descriptor rather than a fixed-size staging buffer. This is the same class of bug commit 2f1763f62909 ("HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq") already hardened in the sibling wacom_intuos_bt_irq(), which guards each report id against its minimum length before parsing. Guard wacom_intuos_pro2_bt_irq() the same way: before parsing, reject reports shorter than the furthest offset the selected branch actually dereferences, warn, and bail out. Because the whole pen/touch/pad/ battery chain runs unconditionally per branch, a single up-front check against the maximum offset (286 bytes for INTUOSP2_BT/INTUOSP2S_BT, 46 bytes for the gen3 branch) bounds every sub-parser. Returning 0 on a short report also skips those calls for the same malformed report, which is the safe, conservative behavior.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 7.3-rc2; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <96dd0af7597aba2d80cc97e2f66e8b72d30ba125; patch: 6.18.51; patch: 6.6.157; patch: 5.10.270; patch: 0; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <114af803e409a68e52516810ecd24df4d8ce0c68; patch: 6.1.188; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <84781a1f3c5dc6650480be9329e6e8528939eaa0; patch: 5.15.221; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <0cdc6cb242dd8d2731956fdf3390de094482a4b2; patch: 7.2.5; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <d2844f3fcd058113acbe0aa110ab13ef28b98d9f; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <1bfc0547b81d5861443420d19b5ed2fd533cd17f; patch: 6.12.110; 4.11; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <a8e04f3f894ccb52cfcd7e60125a9f35da4a616d; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <74ec08f7b81c2726578039ca6dea0fec136c38ea
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.