PT-2026-82904 · Linux · Linux

CVE-2026-80604

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
HID: core: Fix OOB read in hid get report for numbered reports
When a caller passes a size of 0 to hid report raw event() for a numbered report, the function originally called hid get report() before performing any size validation.
Inside hid get report(), if the report is numbered (report enum->numbered is true), it unconditionally dereferences data[0] to extract the report ID. With a size of 0, this results in an out-of-bounds read or kernel panic.
Fix this by moving the numbered report size validation check before the call to hid get report(), ensuring that size is at least 1 before dereferencing the data pointer.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80604

Affected Products

Linux