CVE-2022-48978: HID: core: fix shift-out-of-bounds in hid_report_raw_event
In the Linux kernel, the following vulnerability has been resolved:
HID: core: fix shift-out-of-bounds in hid_report_raw_event
Syzbot reported shift-out-of-bounds in hid_report_raw_event.
microsoft 0003:045E:07DA.0001: hid_field_extract() called with n (128) >
32! (swapper/0)
======================================================================
UBSAN: shift-out-of-bounds in drivers/hid/hid-core.c:1323:20
shift exponent 127 is too large for 32-bit type 'int'
CPU: 0 PID: 0 Comm: swapper/0 Not tainted
6.1.0-rc4-syzkaller-00159-g4bbf3422df78 #0
Hardware name: Google Compute Engine/Google Compute Engine, BIOS
Google 10/26/2022
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
ubsan_epilogue lib/ubsan.c:151 [inline]
__ubsan_handle_shift_out_of_bounds+0x3a6/0x420 lib/ubsan.c:322
snto32 drivers/hid/hid-core.c:1323 [inline]
hid_input_fetch_field drivers/hid/hid-core.c:1572 [inline]
hid_process_report drivers/hid/hid-core.c:1665 [inline]
hid_report_raw_event+0xd56/0x18b0 drivers/hid/hid-core.c:1998
hid_input_report+0x408/0x4f0 drivers/hid/hid-core.c:2066
hid_irq_in+0x459/0x690 drivers/hid/usbhid/hid-core.c:284
__usb_hcd_giveback_urb+0x369/0x530 drivers/usb/core/hcd.c:1671
dummy_timer+0x86b/0x3110 drivers/usb/gadget/udc/dummy_hcd.c:1988
call_timer_fn+0xf5/0x210 kernel/time/timer.c:1474
expire_timers kernel/time/timer.c:1519 [inline]
__run_timers+0x76a/0x980 kernel/time/timer.c:1790
run_timer_softirq+0x63/0xf0 kernel/time/timer.c:1803
__do_softirq+0x277/0x75b kernel/softirq.c:571
__irq_exit_rcu+0xec/0x170 kernel/softirq.c:650
irq_exit_rcu+0x5/0x20 kernel/softirq.c:662
sysvec_apic_timer_interrupt+0x91/0xb0 arch/x86/kernel/apic/apic.c:1107
======================================================================
If the size of the integer (unsigned n) is bigger than 32 in snto32(),
shift exponent will be too large for 32-bit type 'int', resulting in a
shift-out-of-bounds bug.
Fix this by adding a check on the size of the integer (unsigned n) in
snto32(). To add support for n greater than 32 bits, set n to 32, if n
is greater than 32.
Security readout for executives and security teams
Plain-English summary
CVE-2022-48978 is a Linux kernel HID input handling bug. A malformed or unusual HID report can trigger an invalid bit shift in kernel code. The public record shows it was found by syzbot and fixed in upstream stable commits. No source in the bundle shows active exploitation or a public exploit.
Executive priority
Treat as a kernel maintenance item with uncertain severity. Prioritize patching where untrusted HID devices or USB passthrough are realistic. Do not escalate as actively exploited based on the provided evidence.
Technical view
The bug is in hid_report_raw_event, through snto32 and hid_input_fetch_field. When unsigned n is greater than 32, the code can shift by an invalid exponent for a 32-bit int. The fix adds a size check and caps n at 32 when needed. The bundle lists Linux kernels from 2.6.20 through 6.1-related stable lines as affected.
Likely exposure
Exposure is most relevant to Linux systems processing HID input, especially USB HID devices or virtualized HID paths. Servers with no untrusted HID attachment surface are likely less exposed, but kernel version and distribution backports must be checked.
Exploitation context
The source bundle reports a syzbot crash with UBSAN shift-out-of-bounds diagnostics. KEV is false, and no cited source states active exploitation. The record does not provide exploitability, privilege impact, or confidentiality impact details.
Researcher notes
The record lacks CVSS, CWE, and exploitability analysis. The trace shows IRQ-context HID processing and dummy_hcd during syzkaller testing. Validation should focus on code provenance, distro backports, and whether local device policy creates a meaningful HID input attack surface.
Mitigation direction
Update to a vendor-supported kernel containing the upstream HID fix.
Confirm distribution kernel advisories or backports for CVE-2022-48978.
Restrict untrusted physical or virtual HID devices until patched.
Prioritize exposed workstations, kiosks, lab systems, and virtualization hosts with USB passthrough.
Validation and detection
Inventory Linux kernel versions across affected fleets.
Check whether the relevant stable fix commit is included or backported.
Review kernel logs for hid_field_extract or UBSAN shift-out-of-bounds messages.
Test patched kernels with normal HID devices for regression risk.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-48978 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.