Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-46906— HID: usbhid: fix info leak in hid_submit_ctrl

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于HID_submit_ctrl存在信息泄露漏洞。

AI Predicted 5.3 Difficulty: Moderate EPSS 0.24% · P14

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< c5d3c142f2d57d40c55e65d5622d319125a45366 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 41b1e71a2c57366b08dcca1a28b0d45ca69429ce affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 8c064eece9a51856f3f275104520c7e3017fc5c0 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 0e280502be1b003c3483ae03fc60dea554fcfa82 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 7f5a4b24cdbd7372770a02f23e347d7d9a9ac8f1 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< b1e3596416d74ce95cc0b7b38472329a3818f8a9 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 21883bff0fd854e07429a773ff18f1e9658f50e8 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 6be388f4a35d2ce5ef7dbf635a8964a5da7f799f affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-46906

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HID: usbhid: fix info leak in hid_submit_ctrl
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report length doesn't take into account that report->size can be zero. When running the syzkaller reproducer, a report of size 0 causes hid_submit_ctrl) to calculate transfer_buffer_length as 16384. When this urb is passed to the usb core layer, KMSAN reports an info leak of 16384 bytes. To fix this, first modify hid_report_len() to account for the zero report size case by using DIV_ROUND_UP for the division. Then, call it from hid_submit_ctrl().
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于HID_submit_ctrl存在信息泄露漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ~ c5d3c142f2d57d40c55e65d5622d319125a45366 -
Linux Linux 2.6.12 -

II. Public POCs for CVE-2021-46906

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-46906

请登录查看更多情报信息。

Other References for CVE-2021-46906 (7)

Same Patch Batch · Linux · 2024-02-26 · 6 CVEs total

CVE-2019-25160 9.1 CRITICAL netlabel: fix out-of-bounds memory accesses
CVE-2019-25162 7.8 HIGH i2c: Fix a potential use after free
CVE-2023-52474 7.8 HIGH IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests
CVE-2024-26606 binder: signal epoll threads of self-work
CVE-2020-36775 f2fs: fix to avoid potential deadlock

IV. Related Vulnerabilities

V. Comments for CVE-2021-46906

No comments yet


Leave a comment