HID: core: Fix OOB read in hid_get_report for numbered reports
Summary
| CVE | CVE-2026-80604 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 08:16:44 UTC |
| Updated | 2026-08-28 08:16:44 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
HID: core: Fix OOB read in hid_get_report for numbered reports
When a caller passes a size of 0 to hid_report_raw_event() for a
numbered report, the function originally called hid_get_report() before
performing any size validation.
Inside hid_get_report(), if the report is numbered (report_enum->numbered
is true), it unconditionally dereferences data[0] to extract the report ID.
With a size of 0, this results in an out-of-bounds read or kernel panic.
Fix this by moving the numbered report size validation check before the
call to hid_get_report(), ensuring that size is at least 1 before
dereferencing the data pointer. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 59bfdb41a34cf5d6af1c637348714c2b5a6ca676 f8896b684e246f3f00f45ba2b6803ae59b9cc768 git |
Not specified |
| CNA |
Linux |
Linux |
affected a4d6cb7cf45bddc76c78ed5fd683328af9e2018f 30ff978af92cb51c9ba99f96fc4f4ac80d7001ba git |
Not specified |
| CNA |
Linux |
Linux |
affected 121dc93ae1fcaa4b9a601eca6b3ca2e969c2fe2f c39f5765ad840b71ff8db812d0210f216cca96e4 git |
Not specified |
| CNA |
Linux |
Linux |
affected 9e36568e67f817c728f9d79049d212da79109a75 c973d53bcd420b58c4a34c68198746286d77e9fa git |
Not specified |
| CNA |
Linux |
Linux |
affected fb3f7ec2606cdc7c6ef30970f381e571866bfd54 c1fc0d3aff26ec9ff885b3e4c92eba98cf349678 git |
Not specified |
| CNA |
Linux |
Linux |
affected 509c2605065004fc4cd86ee50a9350d402785307 dd395744e4ed87956fcbf81ecc6a20c51e35fa4e git |
Not specified |
| CNA |
Linux |
Linux |
affected 2c85c61d1332e1e16f020d76951baf167dcb6f7a f7e8117e42b20c30d2a5edab82c944a5e381d791 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2c85c61d1332e1e16f020d76951baf167dcb6f7a af1a9b65ebe8a948eda805c14b78d4d0767cb1b5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 710a946b1aa2c35dc56f86621f436938f31ba1a5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.10.259 5.10.261 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.15.210 5.15.212 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.1.176 6.1.178 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.143 6.6.145 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12.93 6.12.97 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.18.33 6.18.40 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.0.10 7.1 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.1 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.261 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.212 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.178 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.145 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.97 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.40 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.5 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/f8896b684e246f3f00f45ba2b6803ae59b9cc768 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f7e8117e42b20c30d2a5edab82c944a5e381d791 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c39f5765ad840b71ff8db812d0210f216cca96e4 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/af1a9b65ebe8a948eda805c14b78d4d0767cb1b5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c1fc0d3aff26ec9ff885b3e4c92eba98cf349678 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/30ff978af92cb51c9ba99f96fc4f4ac80d7001ba |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c973d53bcd420b58c4a34c68198746286d77e9fa |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/dd395744e4ed87956fcbf81ecc6a20c51e35fa4e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.