CVE-2024-46747: HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup

Description

In the Linux kernel, the following vulnerability has been resolved:

HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup

report_fixup for the Cougar 500k Gaming Keyboard was not verifying
that the report descriptor size was correct before accessing it

Classification

CVE ID: CVE-2024-46747

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 9.18% (scored less or equal to compared to others)

EPSS Date: 2025-05-07 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-46747
https://git.kernel.org/stable/c/e239e44dcd419b13cf840e2a3a833204e4329714
https://git.kernel.org/stable/c/fac3cb3c6428afe2207593a183b5bc4742529dfd
https://git.kernel.org/stable/c/34185de73d74fdc90e8651cfc472bfea6073a13f
https://git.kernel.org/stable/c/890dde6001b651be79819ef7a3f8c71fc8f9cabf
https://git.kernel.org/stable/c/e4a602a45aecd6a98b4b37482f5c9f8f67a32ddd
https://git.kernel.org/stable/c/30e9ce7cd5591be639b53595c95812f1a2afdfdc
https://git.kernel.org/stable/c/48b2108efa205f4579052c27fba2b22cc6ad8aa0
https://git.kernel.org/stable/c/a6e9c391d45b5865b61e569146304cff72821a5d

Timeline