SB20260905164 - Use-after-free in Linux kernel hid driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-80782)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to use-after-free in the HID magicmouse driver when processing input reports after HID input-device connection failure. An attacker with physical access can cause a subsequent input report to be processed to cause a denial of service.
The affected execution paths are for USB Magic Mouse 2 and Magic Trackpad 2 devices, where hidraw and hiddev remain claimed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc
- https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791
- https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3
- https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd
- https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b
- https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14
- https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3
- https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a
- https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3