PT-2026-93640 · Linux · Linux Kernel

CVE-2026-89999

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read exists in the HID wacom driver. The function wacom intuos pro2 bt irq() receives a wire report length in the len variable but fails to validate it before parsing. A malicious or malfunctioning Bluetooth peripheral can spoof a specific VID/PID and send an undersized report. This causes the driver to read past the received report buffer and forward the data to userspace via evdev. The issue occurs because sub-parsers like wacom intuos pro2 bt pen(), wacom intuos pro2 bt touch(), wacom intuos pro2 bt pad(), wacom intuos pro2 bt battery(), wacom intuos gen3 bt pad(), and wacom intuos gen3 bt battery() dereference wacom->data at fixed offsets without checking the actual length of the report.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101162
CVE-2026-89999
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel