CVE Database
/

CVE-2024-39509

Back to search

CVE-2024-39509

Published: Jul 12, 2024

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: HID: core: remove unnecessary WARN_ON() in implement() Syzkaller hit a warning [1] in a call to implement() when trying to write a value into a field of smaller size in an output report. Since implement() already has a warn message printed out with the help of hid_warn() and value in question gets trimmed with: ... value &= m; ... WARN_ON may be considered superfluous. Remove it to suppress future syzkaller triggers. [1] WARNING: CPU: 0 PID: 5084 at drivers/hid/hid-core.c:1451 implement drivers/hid/hid-core.c:1451 [inline] WARNING: CPU: 0 PID: 5084 at drivers/hid/hid-core.c:1451 hid_output_report+0x548/0x760 drivers/hid/hid-core.c:1863 Modules linked in: CPU: 0 PID: 5084 Comm: syz-executor424 Not tainted 6.9.0-rc7-syzkaller-00183-gcf87f46fd34d #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/02/2024 RIP: 0010:implement drivers/hid/hid-core.c:1451 [inline] RIP: 0010:hid_output_report+0x548/0x760 drivers/hid/hid-core.c:1863 ... Call Trace: <TASK> __usbhid_submit_report drivers/hid/usbhid/hid-core.c:591 [inline] usbhid_submit_report+0x43d/0x9e0 drivers/hid/usbhid/hid-core.c:636 hiddev_ioctl+0x138b/0x1f00 drivers/hid/usbhid/hiddev.c:726 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:890 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f ...

VendorProductVersions

Linux

Linux

affected
95d1c8951e5bd50bb89654a99a7012b1e75646bd - < 955b3764671f3f157215194972d9c01a3a4bd316
affected
95d1c8951e5bd50bb89654a99a7012b1e75646bd - < f9db5fbeffb951cac3f0fb1c2eeffb79785399ca
affected
95d1c8951e5bd50bb89654a99a7012b1e75646bd - < 33f6832798dd3297317901cc1db556ac3ae80c24
affected
95d1c8951e5bd50bb89654a99a7012b1e75646bd - < 8bac61934cd563b073cd30b8cf6d5c758ab5ab26
affected
95d1c8951e5bd50bb89654a99a7012b1e75646bd - < bfd546fc7fd76076f81bf41b85b51ceda30949fd

+3 more versions

Linux

Linux

affected
4.7
unaffected
0 - < 4.7
unaffected
4.19.317 - <= 4.19.*
unaffected
5.4.279 - <= 5.4.*
unaffected
5.10.221 - <= 5.10.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now