CVE-2026-89629

Summary

In the Linux kernel, the following vulnerability has been resolved:

HID: corsair-void: Check size of status and firmware events before reading them

Malformed status and firmware events could cause an out-of-bounds read since the size wasn't being checked. Check the size and warn on unexpected values to avoid this.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux6ea2a6fd3872e60a4d500b548ad65ed94e459ddd < 79465a30050dad62b3c9e7796368db75dac6fa0daffected
LinuxLinux6ea2a6fd3872e60a4d500b548ad65ed94e459ddd < 0329354abba357340ee88452425857f3718b5807affected
LinuxLinux6ea2a6fd3872e60a4d500b548ad65ed94e459ddd < 08d8814521885e67b1bdf6a3036ee264e3e58377affected
LinuxLinux6.13affected
LinuxLinux0 < 6.13unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References