SB20260905165 - Stack-based buffer overflow in Linux kernel hid driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2026-80783)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service or memory corruption.
The vulnerability exists due to a stack-based buffer overflow in magicmouse_raw_event() when processing a crafted HID report containing nested DOUBLE_REPORT_ID packets. An attacker with physical access can send a crafted HID report to cause a denial of service or memory corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/26c45abed62536aabf4033fb6d64cf72e93374e9
- https://git.kernel.org/stable/c/70589b0c005db003f6d8ae4db3c4d54fed7b83e4
- https://git.kernel.org/stable/c/8a10a624996f16628234306b46f0cf36707d78bd
- https://git.kernel.org/stable/c/a33a596d3ad8dfe6c96a368097a028abeee16c17
- https://git.kernel.org/stable/c/bec338b07beb883726b32192c8f01c601bc76fda
- https://git.kernel.org/stable/c/d095de37f78c5f32a4252ef0f99b84ba76550b86
- https://git.kernel.org/stable/c/d16df755b4493b6d37803c628b2c621d096796a8
- https://git.kernel.org/stable/c/db8d634128d2ba88d79c0b601e983ebe14bb0519