CVE-2024-57986: HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections

Published Feb 27, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections

A report in 2019 by the syzbot fuzzer was found to be connected to two errors in the HID core associated with Resolution Multipliers. One of the errors was fixed by commit ea427a222d8b ("HID: core: Fix deadloop in hidapplymultiplier."), but the other has not been fixed.

This error arises because hidapplymultipler() assumes that every Resolution Multiplier control is contained in a Logical Collection, i.e., there's no way the routine can ever set multipliercollection to NULL. This is in spite of the fact that the function starts with a big comment saying:

"The Resolution Multiplier control must be contained in the same Logical Collection as the control(s) to which it is to be applied. ... If no Logical Collection is defined, the Resolution Multiplier is associated with all controls in the report." HID Usage Table, v1.12, Section 4.3.1, p30 Thus, search from the current collection upwards until we find a logical collection...

The comment and the code overlook the possibility that none of the collections found may be a Logical Collection.

The fix is to set the multipliercollection pointer to NULL if the collection found isn't a Logical Collection.

Affected Software

12 affected components
Linux Linux kernel
Linux Linux kernel>=5.0<5.4.291
Linux Linux kernel>=5.5<5.10.235
Linux Linux kernel>=5.11<5.15.179
Linux Linux kernel>=5.16<6.1.129
Linux Linux kernel>=6.2<6.6.76
Linux Linux kernel>=6.7<6.12.13
Linux Linux kernel>=6.13<6.13.2
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel HID core to a version that resolves this vulnerability.

    Patch ea427a222d8b
  2. Upgrade

    Upgrade Linux kernel HID core to a version that resolves this vulnerability.

    Patch ea427a222d8b (

Event History

Feb 27, 2025
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
Description
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Red Hat·03:04 AM
DescriptionSeverityAffected Software
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-57986?

CVE-2024-57986 has a medium severity rating of 5.5 on the CVSS scale.

2

How do I fix CVE-2024-57986?

To fix CVE-2024-57986, ensure you update your Linux kernel to the patched version that addresses the HID: core vulnerability.

3

What systems are affected by CVE-2024-57986?

CVE-2024-57986 affects systems running the Linux kernel, including IBM Verify Identity Access and IBM Security Verify Access.

4

What type of vulnerability is CVE-2024-57986?

CVE-2024-57986 is categorized as a vulnerability in the Linux kernel related to HID core Resolution Multipliers.

5

Is CVE-2024-57986 exploitable?

Yes, CVE-2024-57986 can be exploited under certain conditions, but it requires specific access to the affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203