{"id":"CVE-2026-80604","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Fix OOB read in hid_get_report for numbered reports\n\nWhen a caller passes a size of 0 to hid_report_raw_event() for a\nnumbered report, the function originall…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Fix OOB read in hid_get_report for numbered reports\n\nWhen a caller passes a size of 0 to hid_report_raw_event() for a\nnumbered report, the function originall…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","published":"2026-08-28","updated":"2026-08-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80604","references":[{"url":"https://git.kernel.org/stable/c/30ff978af92cb51c9ba99f96fc4f4ac80d7001ba","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af1a9b65ebe8a948eda805c14b78d4d0767cb1b5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1fc0d3aff26ec9ff885b3e4c92eba98cf349678","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c39f5765ad840b71ff8db812d0210f216cca96e4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c973d53bcd420b58c4a34c68198746286d77e9fa","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd395744e4ed87956fcbf81ecc6a20c51e35fa4e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7e8117e42b20c30d2a5edab82c944a5e381d791","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8896b684e246f3f00f45ba2b6803ae59b9cc768","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00266,"epssPercentile":0.18719,"ingestedAt":"2026-08-29T22:43:16.154Z","slug":"CVE-2026-80604","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Fix OOB read in hid_get_report for numbered reports\n\nWhen a caller passes a size of 0 to hid_report_raw_event() for a\nnumbered report, the function originally called hid_get_report() before\nperforming any size validation.\n\nInside hid_get_report(), if the report is numbered (report_enum->numbered\nis true), it unconditionally dereferences data[0] to extract the report ID.\nWith a size of 0, this results in an out-of-bounds read or kernel panic.\n\nFix this by moving the numbered report size validation check before the\ncall to hid_get_report(), ensuring that size is at least 1 before\ndereferencing the data pointer.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}