Improper input validation in Linux kernel - CVE-2026-43140
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the HID magicmouse driver when processing a forged USB report descriptor. A local attacker can impersonate a magic mouse USB device to trigger a kernel crash.
This issue can be triggered by a fake USB device and is not expected to occur with actual magic mouse devices.
How to mitigate CVE-2026-43140
Sources
- https://git.kernel.org/stable/c/165912d4321c692321c02793068d30700b4e0f1a
- https://git.kernel.org/stable/c/17abd396548035fbd6179ee1a431bd75d49676a7
- https://git.kernel.org/stable/c/243e1165eb03aca97d87aafa9c3130593837a1c2
- https://git.kernel.org/stable/c/36c83c1329dd881f290f7df2feadfb9a21775108
- https://git.kernel.org/stable/c/5bbe266272d86c0657e8253600f3d5b74fb7b2ae
- https://git.kernel.org/stable/c/922bd3e498a4b8e445def6e6ffea2ad3682ad516
- https://git.kernel.org/stable/c/db5ba06e7af9325519a03e52fccf4a9e7c1fd9b2
- https://git.kernel.org/stable/c/f6a3860241fbb556fd72332fa31c5e787004413b