{"id":"CVE-2026-89621","title":"kernel: HID: mcp2221: validate report size in mcp2221_raw_event() (CVE-2026-89621)","summary":"A flaw was found in the Linux kernel's HID (Human Interface Device) mcp2221 driver. A malicious USB device can exploit this vulnerability by sending a specially crafted, short HID report with an invalid size. This can cause the system to r…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T22:37:14+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89621.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89621.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89621"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532406"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89621"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89621"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89621.mbox"},{"url":"https://git.kernel.org/stable/c/127de5919820f88a9d55e8371ad4ac49f625f4c5"},{"url":"https://git.kernel.org/stable/c/2c9a6998c19503626c57a2267bf279e204113079"},{"url":"https://git.kernel.org/stable/c/7c18fb36708a97ff6772825cc087b6d537bbf0d5"},{"url":"https://git.kernel.org/stable/c/bdc6a3af0dd734a326acdb7d6401a3b6a9f4f149"},{"url":"https://git.kernel.org/stable/c/cb38b1f149b7143355b37e86c841acf0076e5c2a"},{"url":"https://git.kernel.org/stable/c/b2c67dc0e30c308647bbd9b9e5d69a44c9d2733d"},{"url":"https://git.kernel.org/stable/c/fffcfa367072628c3144cca17d2a3c3c9e50c057"},{"url":"https://git.kernel.org/stable/c/c1c508e8923911cb458234997e55b7a4b9aa066f"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.0022,"epssPercentile":0.12714,"ingestedAt":"2026-09-14T15:23:07.450Z","slug":"CVE-2026-89621","body":"## Overview\n\nA flaw was found in the Linux kernel's HID (Human Interface Device) mcp2221 driver. A malicious USB device can exploit this vulnerability by sending a specially crafted, short HID report with an invalid size. This can cause the system to read past valid memory, leading to the disclosure of sensitive kernel memory to userspace through the I2C/SMBus read path. This information disclosure could potentially expose confidential system data.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89621.json)\n\n**kernel: HID: mcp2221: validate report size in mcp2221_raw_event()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208070,"id":"CVE-2026-89621","ts":1789922704391,"field":"cvss","old":"4.3","new":"5.5"},{"seq":203959,"id":"CVE-2026-89621","ts":1789490230802,"field":"cvss","old":null,"new":"4.3"},{"seq":203958,"id":"CVE-2026-89621","ts":1789490230802,"field":"severity","old":"none","new":"medium"},{"seq":147217,"id":"CVE-2026-89621","ts":1789270201987,"field":"cvss","old":null,"new":"4.3"},{"seq":147216,"id":"CVE-2026-89621","ts":1789270201987,"field":"severity","old":"none","new":"medium"},{"seq":108972,"id":"CVE-2026-89621","ts":1789183729790,"field":"cvss","old":null,"new":"4.3"},{"seq":108971,"id":"CVE-2026-89621","ts":1789183729790,"field":"severity","old":"none","new":"medium"}]}