SB2026032559 - NULL Pointer Dereference in Linux kernel hid driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL Pointer Dereference (CVE-ID: CVE-2026-23382)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper pointer validation in HID subsystem raw_event callbacks when processing input from unclaimed HID devices. A remote attacker can send specially crafted HID reports to trigger a NULL pointer dereference and crash the system.
Exploitation does not require user interaction or prior authentication.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/20864e3e41c74cda253a9fa6b6fe093c1461a6a9
- https://git.kernel.org/stable/c/575122cd6569c4c4aa13c4c9958fea506724c788
- https://git.kernel.org/stable/c/6e330889e6c8db99f04d4feb861d23de4e8fbb13
- https://git.kernel.org/stable/c/892dbaf46bb738dacf1fa663eadb3712c85868f0
- https://git.kernel.org/stable/c/ac83b0d91a3f4f0c012ba9c85fb99436cddb1208
- https://git.kernel.org/stable/c/ecfa6f34492c493a9a1dc2900f3edeb01c79946b