Out-of-bounds read in Linux kernel - CVE-2026-80575

 

Out-of-bounds read in Linux kernel - CVE-2026-80575

Published: August 27, 2026


Vulnerability identifier: #VU145916
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80575
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to an out-of-bounds read in the cs40l50-vibra driver when processing FF_PERIODIC/FF_CUSTOM effect data supplied through EVIOCSFF. A local user can provide a specially crafted custom data buffer to execute arbitrary code.

The issue can be triggered when the custom data buffer is shorter than the two words later read by the driver, and the bank value handling can also wrap values of 0x8000 or greater to a negative index.


Affected software

Linux kernel

How to mitigate CVE-2026-80575

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins