CVE-2026-80604
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: core: Fix OOB read in hid_get_report for numbered reports
When a caller passes a size of 0 to hid_report_raw_event() for a numbered report, the function originally called hid_get_report() before performing any size validation.
Inside hid_get_report(), if the report is numbered (report_enum->numbered is true), it unconditionally dereferences data[0] to extract the report ID. With a size of 0, this results in an out-of-bounds read or kernel panic.
Fix this by moving the numbered report size validation check before the call to hid_get_report(), ensuring that size is at least 1 before dereferencing the data pointer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 59bfdb41a34cf5d6af1c637348714c2b5a6ca676 < f8896b684e246f3f00f45ba2b6803ae59b9cc768 | affected |
| Linux | Linux | a4d6cb7cf45bddc76c78ed5fd683328af9e2018f < 30ff978af92cb51c9ba99f96fc4f4ac80d7001ba | affected |
| Linux | Linux | 121dc93ae1fcaa4b9a601eca6b3ca2e969c2fe2f < c39f5765ad840b71ff8db812d0210f216cca96e4 | affected |
| Linux | Linux | 9e36568e67f817c728f9d79049d212da79109a75 < c973d53bcd420b58c4a34c68198746286d77e9fa | affected |
| Linux | Linux | fb3f7ec2606cdc7c6ef30970f381e571866bfd54 < c1fc0d3aff26ec9ff885b3e4c92eba98cf349678 | affected |
| Linux | Linux | 509c2605065004fc4cd86ee50a9350d402785307 < dd395744e4ed87956fcbf81ecc6a20c51e35fa4e | affected |
| Linux | Linux | 2c85c61d1332e1e16f020d76951baf167dcb6f7a < f7e8117e42b20c30d2a5edab82c944a5e381d791 | affected |
| Linux | Linux | 2c85c61d1332e1e16f020d76951baf167dcb6f7a < af1a9b65ebe8a948eda805c14b78d4d0767cb1b5 | affected |
| Linux | Linux | 710a946b1aa2c35dc56f86621f436938f31ba1a5 | affected |
| Linux | Linux | 5.10.259 < 5.10.261 | affected |
| Linux | Linux | 5.15.210 < 5.15.212 | affected |
| Linux | Linux | 6.1.176 < 6.1.178 | affected |
| Linux | Linux | 6.6.143 < 6.6.145 | affected |
| Linux | Linux | 6.12.93 < 6.12.97 | affected |
| Linux | Linux | 6.18.33 < 6.18.40 | affected |
| Linux | Linux | 7.0.10 < 7.1 | affected |
| Linux | Linux | 7.1 | affected |
| Linux | Linux | 0 < 7.1 | unaffected |
| Linux | Linux | 5.10.261 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.212 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.178 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.145 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.97 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f8896b684e246f3f00f45ba2b6803ae59b9cc768
- https://git.kernel.org/stable/c/30ff978af92cb51c9ba99f96fc4f4ac80d7001ba
- https://git.kernel.org/stable/c/c39f5765ad840b71ff8db812d0210f216cca96e4
- https://git.kernel.org/stable/c/c973d53bcd420b58c4a34c68198746286d77e9fa
- https://git.kernel.org/stable/c/c1fc0d3aff26ec9ff885b3e4c92eba98cf349678
- https://git.kernel.org/stable/c/dd395744e4ed87956fcbf81ecc6a20c51e35fa4e
- https://git.kernel.org/stable/c/f7e8117e42b20c30d2a5edab82c944a5e381d791
- https://git.kernel.org/stable/c/af1a9b65ebe8a948eda805c14b78d4d0767cb1b5
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.