Use-after-free in Linux kernel - CVE-2026-80782
Published: September 5, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to use-after-free in the HID magicmouse driver when processing input reports after HID input-device connection failure. An attacker with physical access can cause a subsequent input report to be processed to cause a denial of service.
The affected execution paths are for USB Magic Mouse 2 and Magic Trackpad 2 devices, where hidraw and hiddev remain claimed.
Affected software
How to mitigate CVE-2026-80782
External References
- https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc
- https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791
- https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3
- https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd
- https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b
- https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14
- https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3
- https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a
- https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3