Memory leak in Linux kernel - CVE-2026-89627
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper memory release in the ROCcat HID device destruction paths when destroying a device with buffered reports stored in its circular buffer. A local user can trigger the affected device destruction path while buffered reports remain stored to cause a denial of service.
Up to ROCCAT_CBUF_SIZE report buffers per device can become unreachable.