No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Seungjin Bae c4e746651b Input: pegasus-notetaker - fix potential out-of-bounds access
[ Upstream commit 69aeb507312306f73495598a055293fa749d454e ]

In the pegasus_notetaker driver, the pegasus_probe() function allocates
the URB transfer buffer using the wMaxPacketSize value from
the endpoint descriptor. An attacker can use a malicious USB descriptor
to force the allocation of a very small buffer.

Subsequently, if the device sends an interrupt packet with a specific
pattern (e.g., where the first byte is 0x80 or 0x42),
the pegasus_parse_packet() function parses the packet without checking
the allocated buffer size. This leads to an out-of-bounds memory access.

Fixes: 1afca2b66a ("Input: add Pegasus Notetaker tablet driver")
Signed-off-by: Seungjin Bae <eeodqql09@gmail.com>
Link: https://lore.kernel.org/r/20251007214131.3737115-2-eeodqql09@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-12-03 12:45:22 +01:00
arch MIPS: Malta: Fix !EVA SOC-it PCI MMIO 2025-12-03 12:45:20 +01:00
block block: use int to store blk_stack_limits() return value 2025-10-29 13:59:46 +01:00
certs
crypto crypto: essiv - Check ssize for decryption and in-place encryption 2025-10-29 13:59:52 +01:00
Documentation arm64: errata: Apply workarounds for Neoverse-V3AE 2025-10-29 14:00:00 +01:00
drivers Input: pegasus-notetaker - fix potential out-of-bounds access 2025-12-03 12:45:22 +01:00
fs fs/proc: fix uaf in proc_readdir_de() 2025-12-03 12:45:21 +01:00
include usb: deprecate the third argument of usb_maxpacket() 2025-12-03 12:45:21 +01:00
init bpfilter: match bit size of bpfilter_umh to that of the kernel 2025-07-17 18:24:51 +02:00
ipc ipc: fix to protect IPCS lookups using RCU 2025-06-27 11:02:52 +01:00
kernel gcov: add support for GCC 15 2025-12-03 12:45:19 +01:00
lib lib/genalloc: fix device leak in of_gen_pool_get() 2025-10-29 13:59:53 +01:00
LICENSES
mm mm/page_alloc: fix hash table order logging in alloc_large_system_hash() 2025-12-03 12:45:20 +01:00
net net: netpoll: fix incorrect refcount handling causing incorrect cleanup 2025-12-03 12:45:21 +01:00
samples samples: mei: Fix building on musl libc 2025-08-28 16:21:19 +02:00
scripts kconfig/nconf: Initialize the default locale at startup 2025-12-03 12:45:20 +01:00
security KEYS: trusted_tpm1: Compare HMAC values in constant time 2025-10-29 14:00:01 +01:00
sound ALSA: usb-audio: fix uac2 clock source at terminal parser 2025-12-03 12:45:21 +01:00
tools selftests/Makefile: include $(INSTALL_DEP_TARGETS) in clean target to clean net/lib dependency 2025-12-03 12:45:12 +01:00
usr kbuild: hdrcheck: fix cross build with clang 2025-07-17 18:24:51 +02:00
virt KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status 2024-12-19 18:05:04 +01:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS platform: Add Surface platform directory 2025-06-27 11:02:56 +01:00
Makefile Linux 5.4.301 2025-10-29 14:00:02 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.