Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's Human Interface Device (HID) core has been identified, specifically related to the handling of Resolution Multipliers. The issue arises because the function 'hid_apply_multiplier()' incorrectly assumes that all Resolution Multiplier controls are within a Logical Collection. This assumption is flawed, as the function can encounter collections that are not Logical, leading to potential errors. The vulnerability was linked to a report from the syzbot fuzzer in 2019, which highlighted these HID core issues.
The vulnerability can cause a denial of service due to a deadlock situation, where the system becomes unresponsive because the HID core gets stuck in a loop, unable to process inputs or commands effectively.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.