Pointer Type Confusion Vulnerability in Linux Kernel Affecting HID Devices
CVE-2026-80918

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-80918?

A pointer type confusion vulnerability in the Linux kernel's HID subsystem could lead to incorrect handling of long-format items. When HID devices send descriptors including HID_GLOBAL_ITEM_TAG_REPORT_SIZE as long format, it results in the lower part of a kernel pointer being misinterpreted and potentially exposing sensitive information through kernel logging. The vulnerability arises during the processing of HID reports, affecting the accuracy and safety of data handling in HID interactions. Fixes involve ensuring correct identification of item formats to prevent such errors.

Affected Version(s)

Linux 3dc8fc083dbfeede7b63a0c07581192e97711365

Linux 3dc8fc083dbfeede7b63a0c07581192e97711365

Linux 3dc8fc083dbfeede7b63a0c07581192e97711365 < 634f498ea5d5e8e01f8d9414d4f45eeaf9ee1996

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.