LiveActive security incident?Get immediate response
CVE Record

CVE-2022-48978: HID: core: fix shift-out-of-bounds in hid_report_raw_event

In the Linux kernel, the following vulnerability has been resolved: HID: core: fix shift-out-of-bounds in hid_report_raw_event Syzbot reported shift-out-of-bounds in hid_report_raw_event. microsoft 0003:045E:07DA.0001: hid_field_extract() called with n (128) > 32! (swapper/0) ====================================================================== UBSAN: shift-out-of-bounds in drivers/hid/hid-core.c:1323:20 shift exponent 127 is too large for 32-bit type 'int' CPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.1.0-rc4-syzkaller-00159-g4bbf3422df78 #0 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022 Call Trace: <IRQ> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106 ubsan_epilogue lib/ubsan.c:151 [inline] __ubsan_handle_shift_out_of_bounds+0x3a6/0x420 lib/ubsan.c:322 snto32 drivers/hid/hid-core.c:1323 [inline] hid_input_fetch_field drivers/hid/hid-core.c:1572 [inline] hid_process_report drivers/hid/hid-core.c:1665 [inline] hid_report_raw_event+0xd56/0x18b0 drivers/hid/hid-core.c:1998 hid_input_report+0x408/0x4f0 drivers/hid/hid-core.c:2066 hid_irq_in+0x459/0x690 drivers/hid/usbhid/hid-core.c:284 __usb_hcd_giveback_urb+0x369/0x530 drivers/usb/core/hcd.c:1671 dummy_timer+0x86b/0x3110 drivers/usb/gadget/udc/dummy_hcd.c:1988 call_timer_fn+0xf5/0x210 kernel/time/timer.c:1474 expire_timers kernel/time/timer.c:1519 [inline] __run_timers+0x76a/0x980 kernel/time/timer.c:1790 run_timer_softirq+0x63/0xf0 kernel/time/timer.c:1803 __do_softirq+0x277/0x75b kernel/softirq.c:571 __irq_exit_rcu+0xec/0x170 kernel/softirq.c:650 irq_exit_rcu+0x5/0x20 kernel/softirq.c:662 sysvec_apic_timer_interrupt+0x91/0xb0 arch/x86/kernel/apic/apic.c:1107 ====================================================================== If the size of the integer (unsigned n) is bigger than 32 in snto32(), shift exponent will be too large for 32-bit type 'int', resulting in a shift-out-of-bounds bug. Fix this by adding a check on the size of the integer (unsigned n) in snto32(). To add support for n greater than 32 bits, set n to 32, if n is greater than 32.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2022-48978 is a Linux kernel HID input handling bug. A malformed or unusual HID report can trigger an invalid bit shift in kernel code. The public record shows it was found by syzbot and fixed in upstream stable commits. No source in the bundle shows active exploitation or a public exploit.

Executive priority

Treat as a kernel maintenance item with uncertain severity. Prioritize patching where untrusted HID devices or USB passthrough are realistic. Do not escalate as actively exploited based on the provided evidence.

Technical view

The bug is in hid_report_raw_event, through snto32 and hid_input_fetch_field. When unsigned n is greater than 32, the code can shift by an invalid exponent for a 32-bit int. The fix adds a size check and caps n at 32 when needed. The bundle lists Linux kernels from 2.6.20 through 6.1-related stable lines as affected.

Likely exposure

Exposure is most relevant to Linux systems processing HID input, especially USB HID devices or virtualized HID paths. Servers with no untrusted HID attachment surface are likely less exposed, but kernel version and distribution backports must be checked.

Exploitation context

The source bundle reports a syzbot crash with UBSAN shift-out-of-bounds diagnostics. KEV is false, and no cited source states active exploitation. The record does not provide exploitability, privilege impact, or confidentiality impact details.

Researcher notes

The record lacks CVSS, CWE, and exploitability analysis. The trace shows IRQ-context HID processing and dummy_hcd during syzkaller testing. Validation should focus on code provenance, distro backports, and whether local device policy creates a meaningful HID input attack surface.

Mitigation direction

  • Update to a vendor-supported kernel containing the upstream HID fix.
  • Confirm distribution kernel advisories or backports for CVE-2022-48978.
  • Restrict untrusted physical or virtual HID devices until patched.
  • Prioritize exposed workstations, kiosks, lab systems, and virtualization hosts with USB passthrough.

Validation and detection

  • Inventory Linux kernel versions across affected fleets.
  • Check whether the relevant stable fix commit is included or backported.
  • Review kernel logs for hid_field_extract or UBSAN shift-out-of-bounds messages.
  • Test patched kernels with normal HID devices for regression risk.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-48978 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
1ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxdde5845a529ff753364a6d1aea61180946270bfa, dde5845a529ff753364a6d1aea61180946270bfa, dde5845a529ff753364a6d1aea61180946270bfa, dde5845a529ff753364a6d1aea61180946270bfa, dde5845a529ff753364a6d1aea61180946270bfa, dde5845a529ff753364a6d1aea61180946270bfa, dde5845a529ff753364a6d1aea61180946270bfa, dde5845a529ff753364a6d1aea61180946270bfaunaffected
LinuxLinux2.6.20, 0, 4.9.336, 4.14.302, 4.19.269, 5.4.227, 5.10.159, 5.15.83, 6.0.13, 6.1affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.