{"api_version":"1","generated_at":"2026-10-04T11:30:06+00:00","cve":"CVE-2026-97538","urls":{"html":"https://cve.report/CVE-2026-97538","api":"https://cve.report/api/cve/CVE-2026-97538.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97538","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97538"},"summary":{"title":"hwmon: (asus_rog_ryujin) Validate HID report lengths","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (asus_rog_ryujin) Validate HID report lengths\n\nrog_ryujin_raw_event() parses response headers and payload fields without\nfirst checking that they are present in the received report. A short report\ncan therefore make the driver consume uninitialized bytes from the HID\ntransport buffer and expose them as sensor values through sysfs.\n\nValidate the response header and the fields used by each response type\nbefore parsing them.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:04","updated_at":"2026-09-25 11:17:04"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/1caa5f9399ff107a8fa221b1eaca0a9e729d3758","name":"https://git.kernel.org/stable/c/1caa5f9399ff107a8fa221b1eaca0a9e729d3758","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8042312e73c50de82634ce63eae7cf219464b481","name":"https://git.kernel.org/stable/c/8042312e73c50de82634ce63eae7cf219464b481","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97538","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97538","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ed3e03790c5c9f29f032dde9bb784e198984a759 1caa5f9399ff107a8fa221b1eaca0a9e729d3758 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ed3e03790c5c9f29f032dde9bb784e198984a759 8042312e73c50de82634ce63eae7cf219464b481 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc3 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"97538","cve":"CVE-2026-97538","epss":"0.001890000","percentile":"0.076690000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/hwmon/asus_rog_ryujin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"1caa5f9399ff107a8fa221b1eaca0a9e729d3758","status":"affected","version":"ed3e03790c5c9f29f032dde9bb784e198984a759","versionType":"git"},{"lessThan":"8042312e73c50de82634ce63eae7cf219464b481","status":"affected","version":"ed3e03790c5c9f29f032dde9bb784e198984a759","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/hwmon/asus_rog_ryujin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.9"},{"lessThan":"6.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc3","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc3","versionStartIncluding":"6.9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (asus_rog_ryujin) Validate HID report lengths\n\nrog_ryujin_raw_event() parses response headers and payload fields without\nfirst checking that they are present in the received report. A short report\ncan therefore make the driver consume uninitialized bytes from the HID\ntransport buffer and expose them as sensor values through sysfs.\n\nValidate the response header and the fields used by each response type\nbefore parsing them."}],"providerMetadata":{"dateUpdated":"2026-09-25T10:21:36.208Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/1caa5f9399ff107a8fa221b1eaca0a9e729d3758"},{"url":"https://git.kernel.org/stable/c/8042312e73c50de82634ce63eae7cf219464b481"}],"title":"hwmon: (asus_rog_ryujin) Validate HID report lengths","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97538","datePublished":"2026-09-25T10:21:36.208Z","dateReserved":"2026-09-24T16:01:01.153Z","dateUpdated":"2026-09-25T10:21:36.208Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:04","lastModifiedDate":"2026-09-25 11:17:04","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97538","Ordinal":"1","Title":"hwmon: (asus_rog_ryujin) Validate HID report lengths","CVE":"CVE-2026-97538","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97538","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (asus_rog_ryujin) Validate HID report lengths\n\nrog_ryujin_raw_event() parses response headers and payload fields without\nfirst checking that they are present in the received report. A short report\ncan therefore make the driver consume uninitialized bytes from the HID\ntransport buffer and expose them as sensor values through sysfs.\n\nValidate the response header and the fields used by each response type\nbefore parsing them.","Type":"Description","Title":"hwmon: (asus_rog_ryujin) Validate HID report lengths"}]}}}