SB20260828198 - Improper access control in Linux kernel input misc driver
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-80596)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in the ims-pcu sysfs attribute handlers when accessing sysfs attributes through a non-control interface. A local user can access exposed sysfs attributes on a secondary data interface to cause a denial of service.
The issue occurs because the driver exposes device attributes on all interfaces bound to the driver, even though only the primary control interface has the required descriptors and internal state.
Remediation
Install update from vendor's website.