In hidallocreport_buf of hid-core.c, there is a possible leak of kernel memory contents to a USB HID due to uninitialized data. This could lead to physical information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "34146452410896192640336443398141344634", "251583030241243130293964163897364329673", "72787353270723265437437250306612495838", "116944651357710373045126723328057298352" ] }, "id": "ASB-A-380395346-84236873", "source": "https://android.googlesource.com/kernel/common/+/f02dd268a08d4e7ec09ec0ddd2a861ab5a51a0ae", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/hid/hid-core.c", "truncated_path_level": 1.0 }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "34146452410896192640336443398141344634", "251583030241243130293964163897364329673", "72787353270723265437437250306612495838", "116944651357710373045126723328057298352" ] }, "id": "ASB-A-380395346-a2117e1b", "source": "https://android.googlesource.com/kernel/common/+/853ec04e2de45ae6d1fc9476ce52d06582ad87ed", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/hid/hid-core.c", "truncated_path_level": 1.0 }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/f02dd268a08d4e7ec09ec0ddd2a861ab5a51a0ae", "https://android.googlesource.com/kernel/common/+/853ec04e2de45ae6d1fc9476ce52d06582ad87ed" ], "spl": "2025-03-05", "severity": "High", "types": [ "ID" ] }