User Space Data Validation Flaw in Linux Kernel cs40l50-vibra Driver
CVE-2026-80575
What is CVE-2026-80575?
The cs40l50-vibra driver within the Linux kernel has a critical input validation issue that allows for the unsafe copying of user-defined data. When handling custom data from user space, the driver does not enforce length checks, enabling potential memory manipulation and buffer overflows. An attacker can exploit this vulnerability by providing manipulated input, leading to dereferencing of zero-sized or incorrectly allocated memory, which can compromise system integrity. Proper measures, such as enforcing strict length validation and appropriate type handling, are essential to mitigate these risks.
Affected Version(s)
Linux c38fe1bb5d21c2ce0857965ee06174ee587d6b42 < 3855b6a11f8a7aceb8181cc08c99afef58517006
Linux c38fe1bb5d21c2ce0857965ee06174ee587d6b42 < 52a818c586ae2c36b7324bfaefb547f5e866a8ae
Linux c38fe1bb5d21c2ce0857965ee06174ee587d6b42