Stack-based buffer overflow in Linux kernel - CVE-2026-80783
Published: September 5, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service or memory corruption.
The vulnerability exists due to a stack-based buffer overflow in magicmouse_raw_event() when processing a crafted HID report containing nested DOUBLE_REPORT_ID packets. An attacker with physical access can send a crafted HID report to cause a denial of service or memory corruption.
Affected software
How to mitigate CVE-2026-80783
External References
- https://git.kernel.org/stable/c/26c45abed62536aabf4033fb6d64cf72e93374e9
- https://git.kernel.org/stable/c/70589b0c005db003f6d8ae4db3c4d54fed7b83e4
- https://git.kernel.org/stable/c/8a10a624996f16628234306b46f0cf36707d78bd
- https://git.kernel.org/stable/c/a33a596d3ad8dfe6c96a368097a028abeee16c17
- https://git.kernel.org/stable/c/bec338b07beb883726b32192c8f01c601bc76fda
- https://git.kernel.org/stable/c/d095de37f78c5f32a4252ef0f99b84ba76550b86
- https://git.kernel.org/stable/c/d16df755b4493b6d37803c628b2c621d096796a8
- https://git.kernel.org/stable/c/db8d634128d2ba88d79c0b601e983ebe14bb0519