PT-2026-82904 · Linux · Linux
CVE-2026-80604
·
Published
2026-08-28
·
Updated
2026-08-28
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
HID: core: Fix OOB read in hid get report for numbered reports
When a caller passes a size of 0 to hid report raw event() for a
numbered report, the function originally called hid get report() before
performing any size validation.
Inside hid get report(), if the report is numbered (report enum->numbered
is true), it unconditionally dereferences data[0] to extract the report ID.
With a size of 0, this results in an out-of-bounds read or kernel panic.
Fix this by moving the numbered report size validation check before the
call to hid get report(), ensuring that size is at least 1 before
dereferencing the data pointer.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux