{"id":"CVE-2026-89629","title":"kernel: HID: corsair-void: Check size of status and firmware events before reading them (CVE-2026-89629)","summary":"A flaw was found in the Linux kernel, specifically within the `corsair-void` driver for Human Interface Devices (HID). This vulnerability allows an attacker to cause an out-of-bounds read by sending malformed status and firmware events. Th…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T05:13:10+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89629.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89629.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89629"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532529"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89629"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89629"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89629.mbox"},{"url":"https://git.kernel.org/stable/c/79465a30050dad62b3c9e7796368db75dac6fa0d"},{"url":"https://git.kernel.org/stable/c/0329354abba357340ee88452425857f3718b5807"},{"url":"https://git.kernel.org/stable/c/08d8814521885e67b1bdf6a3036ee264e3e58377"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00198,"epssPercentile":0.09832,"ingestedAt":"2026-09-14T11:11:19.885Z","slug":"CVE-2026-89629","body":"## Overview\n\nA flaw was found in the Linux kernel, specifically within the `corsair-void` driver for Human Interface Devices (HID). This vulnerability allows an attacker to cause an out-of-bounds read by sending malformed status and firmware events. The system fails to properly check the size of these events, which could lead to the disclosure of sensitive information or system instability.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89629.json)\n\n**kernel: HID: corsair-void: Check size of status and firmware events before reading them** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203984,"id":"CVE-2026-89629","ts":1789490230919,"field":"cvss","old":null,"new":"5.5"},{"seq":203983,"id":"CVE-2026-89629","ts":1789490230919,"field":"severity","old":"none","new":"medium"},{"seq":147059,"id":"CVE-2026-89629","ts":1789270194984,"field":"cvss","old":null,"new":"5.3"},{"seq":147058,"id":"CVE-2026-89629","ts":1789270194984,"field":"severity","old":"none","new":"medium"}]}