CVE-2026-80765

Summary

In the Linux kernel, the following vulnerability has been resolved:

HID: hyperv: validate initial device info bounds

The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descriptor followed by the report descriptor bytes. mousevsc_on_receive_device_info() trusts bLength and wDescriptorLength without checking that the received packet contains both byte ranges.

A malformed host or backend message can therefore make the guest read past the received VMBus packet while copying the report descriptor. Pass the received initial-device-info size into the parser and reject descriptor lengths that exceed the packet.

Impact: A malicious Hyper-V host or backend can crash a guest by sending a short initial device-info message with an oversized HID report descriptor length.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < e0d5d3e45e142b7ef7525654aaa54d3e986002a6affected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < 390d3d9c52a710fdc9de95a537747397c0c671d1affected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < 8614c043b11cc35ffebd35542ab4da275f8f923daffected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < 334271d3812ab3197c95b4593bc6745f8d189114affected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < f84d777574b748b1a488723ca7be9d87a301a872affected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < 608f8fd8c0f7b6268da43509447802955f210aacaffected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < 2529737763cb4bcfcaf397beeea2664656c865b4affected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < c894143c508a7e063aab9f73c9e835ab40121283affected
LinuxLinuxb95f5bcb811e3905b5376f87789da8d097fee682 < 934b7778aa7b7c8f6bb073d2a73ba3674885bae0affected
LinuxLinux3.3affected
LinuxLinux0 < 3.3unaffected
LinuxLinux5.10.267 <= 5.10.*unaffected
LinuxLinux5.15.218 <= 5.15.*unaffected
LinuxLinux6.1.185 <= 6.1.*unaffected
LinuxLinux6.6.154 <= 6.6.*unaffected
LinuxLinux6.12.106 <= 6.12.*unaffected
LinuxLinux6.18.47 <= 6.18.*unaffected
LinuxLinux7.1.11 <= 7.1.*unaffected
LinuxLinux7.2.1 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References