SB20260828190 - Integer overflow in Linux kernel hid driver
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-80605)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer overflow in picolcd_send_and_wait() when processing crafted input to the HID device. A local user can trigger excessive loop iterations to cause a NULL pointer dereference and crash the kernel.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0021eb09041f021c079be1022934a280f7f176c0
- https://git.kernel.org/stable/c/42dc0b7b55fe0499fc09183f34a1c46d1dcccf77
- https://git.kernel.org/stable/c/48caee2c106b03301c72fe389ebff00d852c58d5
- https://git.kernel.org/stable/c/a02d5d7ad7ae5fa3756b8332f7350e973085dcb3
- https://git.kernel.org/stable/c/d354e523c6f740db758cafcd4c11bb7913285ed8
- https://git.kernel.org/stable/c/dc176447c7279435c46735db7da81aed1ec25cc2
- https://git.kernel.org/stable/c/e4edeefb8d5bfceb2058e2b3291f4ae1e5a76e61
- https://git.kernel.org/stable/c/ef649703dce0df1364fcec3cdad9b32d1c522939