GHSA-9m92-4vqv-mrj9MediumCVSS 5.5
In the Linux kernel, the following vulnerability has been resolved: HID: alps: fix NULL pointer...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
HID: alps: fix NULL pointer dereference in alps_raw_event()
Commit ecfa6f34492c ("HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them") attempted to fix up the HID drivers that had missed the previous fix that was done in 2ff5baa9b527 ("HID: appleir: Fix potential NULL dereference at raw event handle"), but the alps driver was missed.
Fix this up by properly checking in the hid-alps driver that it had been claimed correctly before attempting to process the raw event.
🔗 References (11)
- https://nvd.nist.gov/vuln/detail/CVE-2026-31625
- https://git.kernel.org/stable/c/0091dfa542a362c178a7e9393097138a57d327d1
- https://git.kernel.org/stable/c/4b618248d2307a219d9431a730cfe1156c8e3386
- https://git.kernel.org/stable/c/8eed7bce7a4c41ab28ee4891103623a12fd41611
- https://git.kernel.org/stable/c/ee2cb3ddfdca949dbc0c3f796ed5a439f0efc9f6
- https://git.kernel.org/stable/c/1badfc4319224820d5d890f8eab6aa52e4e83339
- https://git.kernel.org/stable/c/c8cc765253ad89ccc106a7bdeb5aeac6cf963078
- https://git.kernel.org/stable/c/56850666bb5dcf7a13d76c5d02864813e17ee537
- https://git.kernel.org/stable/c/72516a8d7fe247fd895424bab87952f105a0c255
- https://git.kernel.org/stable/c/cc411e4823d8bfa23327d9989a0fa4e0ce76aebe
- https://github.com/advisories/GHSA-9m92-4vqv-mrj9