Out-of-bounds write in Linux kernel - CVE-2026-89619
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the quickspi_get_report() function of the intel-quickspi HID component when copying a device-supplied GET_REPORT response into a caller-provided buffer. A local user can request an input or feature report through hidraw with a buffer smaller than the returned response to cause memory corruption.