{"api_version":"1","generated_at":"2026-08-29T12:11:53+00:00","cve":"CVE-2026-80596","urls":{"html":"https://cve.report/CVE-2026-80596","api":"https://cve.report/api/cve/CVE-2026-80596.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80596","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80596"},"summary":{"title":"Input: ims-pcu - only expose sysfs attributes on control interface","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - only expose sysfs attributes on control interface\n\nWhen the driver was converted to use the driver core to instantiate device\nattributes (via .dev_groups in the usb_driver structure), the attributes\nstarted appearing on all interfaces bound to the driver. Since the ims-pcu\ndriver manually claims the secondary data interface during probe, the\ndriver core automatically creates the sysfs attributes for that interface\nas well.\n\nHowever, the driver only supports these attributes on the primary control\ninterface. Data interfaces lack the necessary descriptors and internal\nstate to handle these requests, and accessing them can lead to unexpected\nbehavior or crashes.\n\nFix this by updating the is_visible() callbacks for both the main and OFN\nattribute groups to verify that the interface being accessed is indeed the\ncontrol interface.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-28 08:16:43","updated_at":"2026-08-29 07:16:44"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/87e2f89dea078572fb9e13864cec2b1bd8e89b71","name":"https://git.kernel.org/stable/c/87e2f89dea078572fb9e13864cec2b1bd8e89b71","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/73e6687be0c1c323a8ec5b733f29440a93e08ff2","name":"https://git.kernel.org/stable/c/73e6687be0c1c323a8ec5b733f29440a93e08ff2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7d5e7c8d48f0aaeb9ec90a9a4f450f3c5e422431","name":"https://git.kernel.org/stable/c/7d5e7c8d48f0aaeb9ec90a9a4f450f3c5e422431","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/001428ea4d2c371107cb984108e266adf99f1f1e","name":"https://git.kernel.org/stable/c/001428ea4d2c371107cb984108e266adf99f1f1e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80596","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80596","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204d18a7a0c67352857dee1bbac517ed63f01d8e 7d5e7c8d48f0aaeb9ec90a9a4f450f3c5e422431 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204d18a7a0c67352857dee1bbac517ed63f01d8e 87e2f89dea078572fb9e13864cec2b1bd8e89b71 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204d18a7a0c67352857dee1bbac517ed63f01d8e 73e6687be0c1c323a8ec5b733f29440a93e08ff2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204d18a7a0c67352857dee1bbac517ed63f01d8e 001428ea4d2c371107cb984108e266adf99f1f1e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80596","cve":"CVE-2026-80596","epss":"0.001680000","percentile":"0.062720000","score_date":"2026-08-28","updated_at":"2026-08-29 00:12:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"7d5e7c8d48f0aaeb9ec90a9a4f450f3c5e422431","status":"affected","version":"204d18a7a0c67352857dee1bbac517ed63f01d8e","versionType":"git"},{"lessThan":"87e2f89dea078572fb9e13864cec2b1bd8e89b71","status":"affected","version":"204d18a7a0c67352857dee1bbac517ed63f01d8e","versionType":"git"},{"lessThan":"73e6687be0c1c323a8ec5b733f29440a93e08ff2","status":"affected","version":"204d18a7a0c67352857dee1bbac517ed63f01d8e","versionType":"git"},{"lessThan":"001428ea4d2c371107cb984108e266adf99f1f1e","status":"affected","version":"204d18a7a0c67352857dee1bbac517ed63f01d8e","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.11"},{"lessThan":"6.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - only expose sysfs attributes on control interface\n\nWhen the driver was converted to use the driver core to instantiate device\nattributes (via .dev_groups in the usb_driver structure), the attributes\nstarted appearing on all interfaces bound to the driver. Since the ims-pcu\ndriver manually claims the secondary data interface during probe, the\ndriver core automatically creates the sysfs attributes for that interface\nas well.\n\nHowever, the driver only supports these attributes on the primary control\ninterface. Data interfaces lack the necessary descriptors and internal\nstate to handle these requests, and accessing them can lead to unexpected\nbehavior or crashes.\n\nFix this by updating the is_visible() callbacks for both the main and OFN\nattribute groups to verify that the interface being accessed is indeed the\ncontrol interface."}],"metrics":[{"cvssV3_1":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached by local sysfs read(2)/write(2) on ims-pcu driver attributes under /sys/bus/usb/devices/*, flowing through kernfs into ims_pcu_is_attr_visible() and the attribute show/store handlers; exploitation does not require remote network traffic or only plugging a USB cable without OS-level sysfs access.\nAC:L - Once an IMS PCU (or compatible malicious USB gadget) is bound and the data interface exposes the duplicated dev_groups attributes, an attacker can deterministically trigger the fault by reading or writing those sysfs files on the data-interface kobject without races or uncontrollable victim state.\nPR:N - Several exposed attributes are S_IRUGO (world-readable), and sysfs directory listing invokes is_visible() without write privileges; any local user who can read /sys can reach the vulnerable callbacks on the data interface without CAP_SYS_ADMIN or init-namespace root.\nUI:N - No cooperative victim action beyond the attacker performing the sysfs access themselves is required; the attacker does not need another user to mount filesystems, open applications, or perform GUI operations at exploit time.\nS:U - Impact is kernel memory corruption, device reset, or firmware-update misuse within the host OS boundary on systems carrying IMS Passenger Control Units (aircraft seats, kiosks); it enables local privilege escalation but does not cross VM, IOMMU, or hypervisor isolation.\nC:H - Invoking control-only sysfs handlers from the data interface can corrupt shared ims_pcu command/URB state or dereference invalid interface data during is_visible/show paths, giving out-of-bounds reads or kernel pointer exposure beyond a pure NULL crash.\nI:H - Writable sysfs stores (reset_device, update_firmware, OFN register writes) on the wrong interface drive ims_pcu_execute_command() against incompletely initialized USB state, enabling arbitrary device reprogramming and heap corruption primitives exploitable for kernel control-flow hijack.\nA:H - The fix description explicitly cites crashes from accessing data-interface sysfs attributes; malformed command/URB handling and NULL or inconsistent pcu state during teardown can trigger kernel oops, panic, or hung USB I/O on in-service passenger-control and kiosk systems."}]}],"providerMetadata":{"dateUpdated":"2026-08-29T06:21:08.760Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/7d5e7c8d48f0aaeb9ec90a9a4f450f3c5e422431"},{"url":"https://git.kernel.org/stable/c/87e2f89dea078572fb9e13864cec2b1bd8e89b71"},{"url":"https://git.kernel.org/stable/c/73e6687be0c1c323a8ec5b733f29440a93e08ff2"},{"url":"https://git.kernel.org/stable/c/001428ea4d2c371107cb984108e266adf99f1f1e"}],"title":"Input: ims-pcu - only expose sysfs attributes on control interface","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80596","datePublished":"2026-08-28T06:48:22.892Z","dateReserved":"2026-08-26T14:34:25.770Z","dateUpdated":"2026-08-29T06:21:08.760Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-28 08:16:43","lastModifiedDate":"2026-08-29 07:16:44","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80596","Ordinal":"1","Title":"Input: ims-pcu - only expose sysfs attributes on control interfa","CVE":"CVE-2026-80596","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80596","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - only expose sysfs attributes on control interface\n\nWhen the driver was converted to use the driver core to instantiate device\nattributes (via .dev_groups in the usb_driver structure), the attributes\nstarted appearing on all interfaces bound to the driver. Since the ims-pcu\ndriver manually claims the secondary data interface during probe, the\ndriver core automatically creates the sysfs attributes for that interface\nas well.\n\nHowever, the driver only supports these attributes on the primary control\ninterface. Data interfaces lack the necessary descriptors and internal\nstate to handle these requests, and accessing them can lead to unexpected\nbehavior or crashes.\n\nFix this by updating the is_visible() callbacks for both the main and OFN\nattribute groups to verify that the interface being accessed is indeed the\ncontrol interface.","Type":"Description","Title":"Input: ims-pcu - only expose sysfs attributes on control interfa"}]}}}