Description
In the Linux kernel, the following vulnerability has been resolved: Input: pegasus-notetaker - fix potential out-of-bounds access In the pegasus_notetaker driver, the pegasus_probe() function allocates the URB transfer buffer using the wMaxPacketSize value from the endpoint descriptor. An attacker can use a malicious USB descriptor to force the allocation of a very small buffer. Subsequently, if the device sends an interrupt packet with a specific pattern (e.g., where the first byte is 0x80 or 0x42), the pegasus_parse_packet() function parses the packet without checking the allocated buffer size. This leads to an out-of-bounds memory access.
Product status
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before c4e746651bd74c38f581e1cf31651119a94de8cd
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before 36bc92b838ff72f62f2c17751a9013b29ead2513
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before 015b719962696b793997e8deefac019f816aca77
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before 084264e10e2ae8938a54355123ad977eb9df56d6
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before d344ea1baf1946c90f0cd6f9daeb5f3e0a0ca479
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before 9ab67eff6d654e34ba6da07c64761aa87c2a3c26
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before 763c3f4d2394a697d14af1335d3bb42f05c9409f
1afca2b66aac7ac262d3511c68725e9e7053b40f (git) before 69aeb507312306f73495598a055293fa749d454e
4.8
Any version before 4.8
5.4.302 (semver)
5.10.247 (semver)
5.15.197 (semver)
6.1.159 (semver)
6.6.118 (semver)
6.12.60 (semver)
6.17.10 (semver)
6.18 (original_commit_for_fix)
References
git.kernel.org/...c/c4e746651bd74c38f581e1cf31651119a94de8cd
git.kernel.org/...c/36bc92b838ff72f62f2c17751a9013b29ead2513
git.kernel.org/...c/015b719962696b793997e8deefac019f816aca77
git.kernel.org/...c/084264e10e2ae8938a54355123ad977eb9df56d6
git.kernel.org/...c/d344ea1baf1946c90f0cd6f9daeb5f3e0a0ca479
git.kernel.org/...c/9ab67eff6d654e34ba6da07c64761aa87c2a3c26
git.kernel.org/...c/763c3f4d2394a697d14af1335d3bb42f05c9409f
git.kernel.org/...c/69aeb507312306f73495598a055293fa749d454e
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.