CVE-2026-63947

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: HIDP: fix missing length checks in hidp_input_report()<br /> <br /> hidp_input_report() reads keyboard and mouse payload data from an skb<br /> without first verifying that skb-&gt;len contains enough data.<br /> <br /> hidp_recv_intr_frame() pulls the 1-byte HIDP header before dispatching<br /> to hidp_input_report(). If a paired device sends a truncated packet,<br /> the handler reads beyond the valid skb data, resulting in an<br /> out-of-bounds read of skb data. The OOB bytes may be interpreted as<br /> phantom key presses or spurious mouse movement.<br /> <br /> Replace the open-coded length tracking and pointer arithmetic with<br /> skb_pull_data() calls. skb_pull_data() returns NULL if the requested<br /> bytes are not present, eliminating the need for a manual size variable<br /> and the separate skb-&gt;len guard.