SB2026090995 - Type Confusion in Linux kernel hid driver
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Type Confusion (CVE-ID: CVE-2026-80918)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose kernel pointer information.
The vulnerability exists due to type confusion in item_udata() and item_sdata() in the HID core when processing long-format HID descriptor items. An attacker with physical access can connect a HID device containing a crafted long-format report size item to disclose kernel pointer information.
The issue affects hid_scan_report(); hid_parse_collections() stops processing when it encounters a long item.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1fa1591efd417e39e5e164bebea8ca7a3837c469
- https://git.kernel.org/stable/c/28abce951343fcec26e397610868efa4e1395c3f
- https://git.kernel.org/stable/c/634f498ea5d5e8e01f8d9414d4f45eeaf9ee1996
- https://git.kernel.org/stable/c/abec577de5fc16cd5caae42f97cdcd0983c06d66
- https://git.kernel.org/stable/c/aec2c2ec87d4ec1f098979f68cd81b29f031c8cb
- https://git.kernel.org/stable/c/bed7fe3a936b6bdd84671385951397ca673cf6e7
- https://git.kernel.org/stable/c/dd8035dec26e98204d6e4a6e0cee5c4d329b3d7e
- https://git.kernel.org/stable/c/e542edada3f79387c0ac2a528cebf01f4ef47df8
- https://git.kernel.org/stable/c/e60159f5ea60254a5c3de4ea4f2f939f0171031b