SB20260828198 - Improper access control in Linux kernel input misc driver



SB20260828198 - Improper access control in Linux kernel input misc driver

Published: August 28, 2026

Security Bulletin ID SB20260828198
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-80596)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper access control in the ims-pcu sysfs attribute handlers when accessing sysfs attributes through a non-control interface. A local user can access exposed sysfs attributes on a secondary data interface to cause a denial of service.

The issue occurs because the driver exposes device attributes on all interfaces bound to the driver, even though only the primary control interface has the required descriptors and internal state.


Remediation

Install update from vendor's website.