Type conversion in Linux kernel - CVE-2026-80774
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of a HID device's USB parent in the ASUS HID driver when handling a uhid-created device that identifies as being on BUS_USB. A local user can create a uhid device with a non-USB parent to trigger a kernel splat and cause a denial of service.
Affected software
How to mitigate CVE-2026-80774
External References
- https://git.kernel.org/stable/c/02bf61dfb44f17ec187d1da1a82495951bbd12df
- https://git.kernel.org/stable/c/1ddc2f5913bec7a846544d51a8f7a8119573b2a1
- https://git.kernel.org/stable/c/8b5debb6252cd1e2b6c7adf8f95761a0e743d2cf
- https://git.kernel.org/stable/c/bdb2e0a2a359e473ca5619e35adee89028697239
- https://git.kernel.org/stable/c/ee883906cf6685d753af9c2d2ca9fd6f63197726