PT-2026-85606 · Linux · Linux

CVE-2026-80765

·

Published

2026-09-04

·

Updated

2026-09-04

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
HID: hyperv: validate initial device info bounds
The Hyper-V synthetic HID host supplies SYNTH HID INITIAL DEVICE INFO messages that contain a HID descriptor followed by the report descriptor bytes. mousevsc on receive device info() trusts bLength and wDescriptorLength without checking that the received packet contains both byte ranges.
A malformed host or backend message can therefore make the guest read past the received VMBus packet while copying the report descriptor. Pass the received initial-device-info size into the parser and reject descriptor lengths that exceed the packet.
Impact: A malicious Hyper-V host or backend can crash a guest by sending a short initial device-info message with an oversized HID report descriptor length.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80765

Affected Products

Linux