Out-of-bounds read in Linux kernel - CVE-2026-80573
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the iforce input packet processing logic when parsing crafted USB input packets. A local attacker can send crafted short packets to trigger out-of-bounds reads and cause a denial of service.
Exploitation requires delivery of malformed data through a connected USB device.
Affected software
How to mitigate CVE-2026-80573
External References
- https://git.kernel.org/stable/c/0ec411167655ef3ff3e84f6af685e962aff9a75b
- https://git.kernel.org/stable/c/2c083ab16e33fbff3ab8c752fbf8118ed3dd31ce
- https://git.kernel.org/stable/c/5232529eaf57f08fe37484e301579a1915b93d14
- https://git.kernel.org/stable/c/5751c781d3c97ab6ce0e2a966156ed882152c415
- https://git.kernel.org/stable/c/609be40988898a4d75225ade0ea5c1734757dd33
- https://git.kernel.org/stable/c/84e5cb517f445dadbd5f8bf4ec513540e51f9c36
- https://git.kernel.org/stable/c/a64a8b6b31cd669f0449138e53cc2592d454ccf1
- https://git.kernel.org/stable/c/e73d7a7d913d89141321f5f3f16343ecc200d152