CVE-2026-80604 PUBLISHED

HID: core: Fix OOB read in hid_get_report for numbered reports

Assigner: Linux
Reserved: 26.08.2026 Published: 28.08.2026 Updated: 28.08.2026

In the Linux kernel, the following vulnerability has been resolved:

HID: core: Fix OOB read in hid_get_report for numbered reports

When a caller passes a size of 0 to hid_report_raw_event() for a numbered report, the function originally called hid_get_report() before performing any size validation.

Inside hid_get_report(), if the report is numbered (report_enum->numbered is true), it unconditionally dereferences data[0] to extract the report ID. With a size of 0, this results in an out-of-bounds read or kernel panic.

Fix this by moving the numbered report size validation check before the call to hid_get_report(), ensuring that size is at least 1 before dereferencing the data pointer.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 59bfdb41a34cf5d6af1c637348714c2b5a6ca676 to f8896b684e246f3f00f45ba2b6803ae59b9cc768 (excl.)
  • affected from a4d6cb7cf45bddc76c78ed5fd683328af9e2018f to 30ff978af92cb51c9ba99f96fc4f4ac80d7001ba (excl.)
  • affected from 121dc93ae1fcaa4b9a601eca6b3ca2e969c2fe2f to c39f5765ad840b71ff8db812d0210f216cca96e4 (excl.)
  • affected from 9e36568e67f817c728f9d79049d212da79109a75 to c973d53bcd420b58c4a34c68198746286d77e9fa (excl.)
  • affected from fb3f7ec2606cdc7c6ef30970f381e571866bfd54 to c1fc0d3aff26ec9ff885b3e4c92eba98cf349678 (excl.)
  • affected from 509c2605065004fc4cd86ee50a9350d402785307 to dd395744e4ed87956fcbf81ecc6a20c51e35fa4e (excl.)
  • affected from 2c85c61d1332e1e16f020d76951baf167dcb6f7a to f7e8117e42b20c30d2a5edab82c944a5e381d791 (excl.)
  • affected from 2c85c61d1332e1e16f020d76951baf167dcb6f7a to af1a9b65ebe8a948eda805c14b78d4d0767cb1b5 (excl.)
  • Version 710a946b1aa2c35dc56f86621f436938f31ba1a5 is affected
  • affected from 5.10.259 to 5.10.261 (excl.)
  • affected from 5.15.210 to 5.15.212 (excl.)
  • affected from 6.1.176 to 6.1.178 (excl.)
  • affected from 6.6.143 to 6.6.145 (excl.)
  • affected from 6.12.93 to 6.12.97 (excl.)
  • affected from 6.18.33 to 6.18.40 (excl.)
  • affected from 7.0.10 to 7.1 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.1 is affected
  • unaffected from 0 to 7.1 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References