CVE-2026-89999
CVE CVE-2026-89999EUVD EUVD-2026-80607Published 2026-09-16T10:33:10.000ZLast changed 2026-09-16T14:41:14.000ZCVSS 8.1
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: validate report length in wacom_intuos_pro2_bt_irq wacom_intuos_pro2_bt_irq() receives the wire report length in `len` but never consults it before parsing. After the report-id gate it unconditionally calls wacom_intuos_pro2_bt_pen() and then, selected by features.type, a fixed chain of sub-parsers, none of which receive `len`: wacom_intuos_pro2_bt_pen(wacom); if (type == INTUOSP2_BT || type == INTUOSP2S_BT) { wacom_intuos_pro2_bt_touch(wacom); wacom_intuos_pro2_bt_pad(wacom); wacom_intuos_pro2_bt_battery(wacom); } else { wacom_intuos_gen3_bt_pad(wacom); wacom_intuos_gen3_bt_battery(wacom); } Each sub-parser dereferences wacom->data at fixed offsets. The furthest byte touched on each branch is: INTUOSP2_BT / INTUOSP2S_BT: wacom_intuos_pro2_bt_pad() reads data[285] (the touchring byte), so the report must be at least 286 bytes; INTUOSHT3_BT ("gen3"): wacom_intuos_gen3_bt_battery() reads data[45], so the report must be at least 46 bytes. features.type is selected from the VID/PID id_table entry and wacom_setup_device_quirks() force-registers the pen/pad/touch inputs for that type independent of the report descriptor, so a malicious or malfunctioning paired/spoofed Bluetooth peripheral can advertise that VID/PID and send an undersized report that still satisfies the data[0] == 0x80/0x81 gate. The driver then reads past the received report and forwards the bytes to userspace via evdev (MSC_SERIAL / ABS_MISC / ABS_WHEEL on the pen and pad input nodes), an out-of-bounds read with a concrete userspace read-back channel, and a true out-of-bounds read on transports whose backing buffer is sized to the (small) report descriptor rather than a fixed-size staging buffer. This is the same class of bug commit 2f1763f62909 ("HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq") already hardened in the sibling wacom_intuos_bt_irq(), which guards each report id against its minimum length before parsing. Guard wacom_intuos_pro2_bt_irq() the same way: before parsing, reject reports shorter than the furthest offset the selected branch actually dereferences, warn, and bail out. Because the whole pen/touch/pad/ battery chain runs unconditionally per branch, a single up-front check against the maximum offset (286 bytes for INTUOSP2_BT/INTUOSP2S_BT, 46 bytes for the gen3 branch) bounds every sub-parser. Returning 0 on a short report also skips those calls for the same malformed report, which is the safe, conservative behavior.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.3-rc2; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <96dd0af7597aba2d80cc97e2f66e8b72d30ba125; patch: 6.18.51; patch: 6.6.157; patch: 5.10.270; patch: 0; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <114af803e409a68e52516810ecd24df4d8ce0c68; patch: 6.1.188; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <84781a1f3c5dc6650480be9329e6e8528939eaa0; patch: 5.15.221; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <0cdc6cb242dd8d2731956fdf3390de094482a4b2; patch: 7.2.5; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <d2844f3fcd058113acbe0aa110ab13ef28b98d9f; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <1bfc0547b81d5861443420d19b5ed2fd533cd17f; patch: 6.12.110; 4.11; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <a8e04f3f894ccb52cfcd7e60125a9f35da4a616d; 4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b <74ec08f7b81c2726578039ca6dea0fec136c38ea
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.