Improper input validation in Linux kernel - CVE-2026-80861
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the xHCI controller setup routine when initializing an inaccessible xHCI controller. A local user can trigger controller setup while the capability register returns an all-ones value to cause a denial of service.
The issue can cause an alignment fault on arm64 systems.