SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80604

HIGH · CVSS 8.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's HID subsystem, specifically in the handling of numbered reports within the `hid_get_report` function. An attacker could exploit this flaw by passing a size of 0 to `hid_report_raw_event()`, leading to an out-of-bounds read or potential kernel panic. System administrators and developers managing Linux environments should prioritize applying the fix to mitigate risks associated with this vulnerability.

CVE
CVE-2026-80604
Severity
HIGH
CVSS
8.8
EPSS
0.27%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix OOB read in hid_get_report for numbered reports When a caller passes a size of 0 to hid_report_raw_event() for a numbered report, the function originally called hid_get_report() before performing any size validation. Inside hid_get_report(), if the report is numbered (report_enum->numbered is true), it unconditionally dereferences data[0] to extract the report ID. With a size of 0, this results in an out-of-bounds read or kernel panic. Fix this by moving the numbered report size validation check before the call to hid_get_report(), ensuring that size is at least 1 before dereferencing the data pointer.