Out-of-bounds read in Linux kernel - CVE-2026-80781
Published: September 5, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to read memory beyond the bounds of a HID usage array.
The vulnerability exists due to an out-of-bounds read in hid_set_field() when processing an offset for a HID field. An attacker with physical access can attach a HID device that registers a field with fewer usages than the offsets used by picolcd_fb_send_tile() to read memory beyond the bounds of a HID usage array.
The out-of-bounds dereference occurs when CONFIG_DEBUG_FS is enabled during framebuffer deferred-io work.
Affected software
How to mitigate CVE-2026-80781
External References
- https://git.kernel.org/stable/c/313ead1abed945544703b100a12c5a10fdf78409
- https://git.kernel.org/stable/c/465544b3d6602cfbdc2305d5cbfb7f4954353b63
- https://git.kernel.org/stable/c/4993e1ab85d7d3f4a40d81852170f9665483bbd8
- https://git.kernel.org/stable/c/5215ea00a747eca34cb2f603cfef91fef76c2558
- https://git.kernel.org/stable/c/9a1d7c5f0d82e8665715d5e47c9410c6a97e3748
- https://git.kernel.org/stable/c/a13cdb19fcb223ed41bdab3bab42b98dba87e90b
- https://git.kernel.org/stable/c/a38212687519f2a72f43e62dec1348a690412404
- https://git.kernel.org/stable/c/c1d9c16af51cc6ff92a5a062617d3b022dd01078
- https://git.kernel.org/stable/c/cbcc0e8dea499e5ca86b583372ccb1815cccc570