CVE-2026-80605

Summary

In the Linux kernel, the following vulnerability has been resolved:

HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()

In picolcd_send_and_wait(), an integer overflow of the signed loop counter 'k' can theoretically lead to a NULL pointer dereference of 'raw_data'. If the loop executes more than INT_MAX times, 'k' becomes negative, making the condition 'k < size' true even when 'size' is 0.

Change the type of 'k' to 'unsigned int' to prevent the overflow and eliminate the out-of-bounds access.

Found by Linux Verification Center (linuxtesting.org) with the Svace static analysis tool.

[jkosina@suse.com: extended hash length]

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < 42dc0b7b55fe0499fc09183f34a1c46d1dcccf77affected
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < 48caee2c106b03301c72fe389ebff00d852c58d5affected
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < dc176447c7279435c46735db7da81aed1ec25cc2affected
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < a02d5d7ad7ae5fa3756b8332f7350e973085dcb3affected
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < e4edeefb8d5bfceb2058e2b3291f4ae1e5a76e61affected
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < d354e523c6f740db758cafcd4c11bb7913285ed8affected
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < ef649703dce0df1364fcec3cdad9b32d1c522939affected
LinuxLinuxfabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 < 0021eb09041f021c079be1022934a280f7f176c0affected
LinuxLinux3.7affected
LinuxLinux0 < 3.7unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References