{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80604","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.772Z","datePublished":"2026-08-28T06:48:29.755Z","dateUpdated":"2026-08-29T06:21:15.771Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-29T06:21:15.771Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Fix OOB read in hid_get_report for numbered reports\n\nWhen a caller passes a size of 0 to hid_report_raw_event() for a\nnumbered report, the function originally called hid_get_report() before\nperforming any size validation.\n\nInside hid_get_report(), if the report is numbered (report_enum->numbered\nis true), it unconditionally dereferences data[0] to extract the report ID.\nWith a size of 0, this results in an out-of-bounds read or kernel panic.\n\nFix this by moving the numbered report size validation check before the\ncall to hid_get_report(), ensuring that size is at least 1 before\ndereferencing the data pointer."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - A malicious Bluetooth HID peripheral with numbered reports can reach hid_report_raw_event() during driver probe/feature mapping (e.g., mt_get_feature()) when hid_report_len() is 0, bypassing __hid_input_report(); BT HIDP delivers attacker-controlled descriptors over an adjacent wireless link.\nAC:L - An attacker fully controls the HID report descriptor and GET_REPORT responses; pairing/connecting a device with numbered reports plus a zero-length report ID 0 deterministically calls hid_report_raw_event() with size 0 during probe, with no race or victim-specific heap layout required.\nPR:N - Exploitation requires only a malicious HID peripheral presenting a crafted numbered-report descriptor; the attacker needs no local account, capabilities, or init-namespace privileges on the victim host.\nUI:N - Feature-mapping probe I/O runs automatically during HID enumeration when the device connects or auto-reconnects; no additional victim file-open, mount, or application interaction is needed beyond standard peripheral attachment handled by the kernel.\nS:U - The out-of-bounds read and kernel panic occur entirely within host kernel HID-core processing; impact does not cross a VM, container, or IOMMU boundary to a separate security authority.\nC:H - On numbered-report devices, hid_get_report() dereferences data[0] before any size validation when size is 0, causing an out-of-bounds kernel memory read that may disclose adjacent heap or slab contents.\nI:H - Kernel heap out-of-bounds reads in HID-core can corrupt parser state or be chained with further memory corruption primitives; per kernel guidance, OOB reads in kernel context warrant High integrity impact when exploitation potential exists.\nA:H - The fix commit and CVE description state that dereferencing data[0] with size 0 on numbered reports can cause a kernel panic; this is a kernel oops-class failure denying system availability until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-core.c"],"versions":[{"version":"59bfdb41a34cf5d6af1c637348714c2b5a6ca676","lessThan":"f8896b684e246f3f00f45ba2b6803ae59b9cc768","status":"affected","versionType":"git"},{"version":"a4d6cb7cf45bddc76c78ed5fd683328af9e2018f","lessThan":"30ff978af92cb51c9ba99f96fc4f4ac80d7001ba","status":"affected","versionType":"git"},{"version":"121dc93ae1fcaa4b9a601eca6b3ca2e969c2fe2f","lessThan":"c39f5765ad840b71ff8db812d0210f216cca96e4","status":"affected","versionType":"git"},{"version":"9e36568e67f817c728f9d79049d212da79109a75","lessThan":"c973d53bcd420b58c4a34c68198746286d77e9fa","status":"affected","versionType":"git"},{"version":"fb3f7ec2606cdc7c6ef30970f381e571866bfd54","lessThan":"c1fc0d3aff26ec9ff885b3e4c92eba98cf349678","status":"affected","versionType":"git"},{"version":"509c2605065004fc4cd86ee50a9350d402785307","lessThan":"dd395744e4ed87956fcbf81ecc6a20c51e35fa4e","status":"affected","versionType":"git"},{"version":"2c85c61d1332e1e16f020d76951baf167dcb6f7a","lessThan":"f7e8117e42b20c30d2a5edab82c944a5e381d791","status":"affected","versionType":"git"},{"version":"2c85c61d1332e1e16f020d76951baf167dcb6f7a","lessThan":"af1a9b65ebe8a948eda805c14b78d4d0767cb1b5","status":"affected","versionType":"git"},{"version":"710a946b1aa2c35dc56f86621f436938f31ba1a5","status":"affected","versionType":"git"},{"version":"5.10.259","lessThan":"5.10.261","status":"affected","versionType":"semver"},{"version":"5.15.210","lessThan":"5.15.212","status":"affected","versionType":"semver"},{"version":"6.1.176","lessThan":"6.1.178","status":"affected","versionType":"semver"},{"version":"6.6.143","lessThan":"6.6.145","status":"affected","versionType":"semver"},{"version":"6.12.93","lessThan":"6.12.97","status":"affected","versionType":"semver"},{"version":"6.18.33","lessThan":"6.18.40","status":"affected","versionType":"semver"},{"version":"7.0.10","lessThan":"7.1","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-core.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.259","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.210","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.176","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.143","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.93","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.33","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.10"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f8896b684e246f3f00f45ba2b6803ae59b9cc768"},{"url":"https://git.kernel.org/stable/c/30ff978af92cb51c9ba99f96fc4f4ac80d7001ba"},{"url":"https://git.kernel.org/stable/c/c39f5765ad840b71ff8db812d0210f216cca96e4"},{"url":"https://git.kernel.org/stable/c/c973d53bcd420b58c4a34c68198746286d77e9fa"},{"url":"https://git.kernel.org/stable/c/c1fc0d3aff26ec9ff885b3e4c92eba98cf349678"},{"url":"https://git.kernel.org/stable/c/dd395744e4ed87956fcbf81ecc6a20c51e35fa4e"},{"url":"https://git.kernel.org/stable/c/f7e8117e42b20c30d2a5edab82c944a5e381d791"},{"url":"https://git.kernel.org/stable/c/af1a9b65ebe8a948eda805c14b78d4d0767cb1b5"}],"title":"HID: core: Fix OOB read in hid_get_report for numbered reports","x_generator":{"engine":"bippy-1.2.0"}}}}