In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: fix missing length checks in hidpinputreport()
hidpinputreport() reads keyboard and mouse payload data from an skb without first verifying that skb->len contains enough data.
hidprecvintrframe() pulls the 1-byte HIDP header before dispatching to hidpinput_report(). If a paired device sends a truncated packet, the handler reads beyond the valid skb data, resulting in an out-of-bounds read of skb data. The OOB bytes may be interpreted as phantom key presses or spurious mouse movement.
Replace the open-coded length tracking and pointer arithmetic with skbpulldata() calls. skbpulldata() returns NULL if the requested bytes are not present, eliminating the need for a manual size variable and the separate skb->len guard.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63947.json",
"cna_assigner": "Linux"
}