Out-of-bounds read in Linux kernel - CVE-2026-90331
Published: September 18, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in the asus_raw_event() handler of the hid-asus driver when processing a keyboard report shorter than two bytes. An attacker with physical access can send a crafted short keyboard report to cause an out-of-bounds read.