Heap-based buffer overflow in Linux kernel - CVE-2026-89620
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in write_cmd_to_txdma() of the intel-quickspi HID driver when handling an oversized hidraw SET_REPORT or SET_FEATURE ioctl. A local user can submit an oversized report to overflow the report buffer and cause a denial of service.