CVE-2026-89628: HID: picolcd: clamp eeprom debugfs read to bytes actually received
HID: picolcd: clamp eeprom debugfs read to bytes actually received
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1 - Configuration
In picolcd_debug_eeprom_read(), before calling copy_to_user(), clamp the copy length to resp->raw_size - 3 (the payload actually received) rather than trusting resp->raw_data[2]; for short replies, floor the computed length at 0.
Linux kernel (hid_picolcd / picolcd_debug_eeprom_read) Clamp length used by copy_to_user to (resp->raw_size - 3) and floor at 0 for short replies = Clamp to resp->raw_size - 3 (payload actually received) before trusting resp->raw_data[2]; if reply is short, use 0
Event History
Frequently Asked Questions
Can this be exploited by an unprivileged local user or remotely?
No. The affected debugfs eeprom file is root-only, and exploitation requires a crafted picoLCD device or a spoofed device returning a malicious REPORT_EE_DATA response.
What can an attacker obtain if exploitation succeeds?
A malicious device can cause the kernel to copy data beyond the 64-byte raw_data buffer into userspace. This may expose adjacent slab memory through the debugfs eeprom file.
Which systems are realistically exposed?
Exposure requires use of the hid_picolcd driver, access to its debugfs eeprom file as root, and interaction with a crafted or spoofed picoLCD device. The issue is not described as remotely or unprivileged-triggerable.