PT-2026-93641 · Linux · Linux Kernel

CVE-2026-90000

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The hid-rmi driver contains an out-of-bounds (OOB) access issue because it determines the size of writeReport and readReport buffers based solely on the report descriptor provided by the device without enforcing minimum bounds. This allows a device to trigger OOB reads and writes when the driver accesses fixed offsets within these buffers.
Technical details include:
  • The read path can read beyond the allocation into adjacent slab objects, potentially leaking heap contents to unprivileged userspace via a sysfs attribute or back to the device itself.
  • The write path allows unbounded copying to the writeReport buffer.
  • A device providing zero-length replies can cause an infinite loop within the probe worker while holding the page mutex, leading to a denial of service.
Vulnerable functions include rmi set page(), rmi hid read block(), rmi f01 probe(), rmi driver set irq bits(), and rmi hid write block().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101123
CVE-2026-90000
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel