CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of input from Touchwindow peripherals, where a malicious or faulty device can exploit the index reset mechanism, leading to an unbounded heap out-of-bounds write. This can potentially allow an attacker to manipulate memory, resulting in arbitrary code execution or system instability. Organizations using Linux systems with Touchwindow devices should prioritize addressing this vulnerability to mitigate risks associated with device-driven memory corruption.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Input: touchwin - reset the packet index on every complete packet tw_interrupt() accumulates each non-zero serial byte into a fixed three-byte buffer with a running index that is only reset once a full packet has been received *and* the device's two Y bytes agree: tw->data[tw->idx++] = data; if (tw->idx == TW_LENGTH && tw->data[1] == tw->data[2]) { ... tw->idx = 0; } The reset is gated on tw->data[1] == tw->data[2], a value the device controls. A malicious, malfunctioning or counterfeit Touchwindow peripheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the index reaches TW_LENGTH without the equality holding, is never reset, and keeps growing, so tw->data[tw->idx++] walks off the end of the three-byte array and the rest of the heap-allocated struct tw, one attacker-chosen byte at a time -- an unbounded, device-driven heap out-of-bounds write. Reset the index on every completed packet and report an event only when the two Y bytes match, like the other serio touchscreen drivers do.
Related CVEs
Other vulnerabilities affecting the same vendor(s)