Integer overflow in Linux kernel - CVE-2026-80605
Published: August 28, 2026
Vulnerability identifier: #VU146275
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80605
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer overflow in picolcd_send_and_wait() when processing crafted input to the HID device. A local user can trigger excessive loop iterations to cause a NULL pointer dereference and crash the kernel.
Affected software
Linux kernel
How to mitigate CVE-2026-80605
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/0021eb09041f021c079be1022934a280f7f176c0
- https://git.kernel.org/stable/c/42dc0b7b55fe0499fc09183f34a1c46d1dcccf77
- https://git.kernel.org/stable/c/48caee2c106b03301c72fe389ebff00d852c58d5
- https://git.kernel.org/stable/c/a02d5d7ad7ae5fa3756b8332f7350e973085dcb3
- https://git.kernel.org/stable/c/d354e523c6f740db758cafcd4c11bb7913285ed8
- https://git.kernel.org/stable/c/dc176447c7279435c46735db7da81aed1ec25cc2
- https://git.kernel.org/stable/c/e4edeefb8d5bfceb2058e2b3291f4ae1e5a76e61
- https://git.kernel.org/stable/c/ef649703dce0df1364fcec3cdad9b32d1c522939