CVE-2026-89621Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's HID (Human Interface Device) mcp2221 driver. A malicious USB device can exploit this vulnerability by sending a specially crafted, short HID report with an invalid size. This can cause the system to r…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.3
none → medium
— → 4.3
none → medium
0.2% → 0.2%
— → 4.3
none → medium
Last analysed / modified upstream
4.3 → 5.5
A flaw was found in the Linux kernel's HID (Human Interface Device) mcp2221 driver. A malicious USB device can exploit this vulnerability by sending a specially crafted, short HID report with an invalid size. This can cause the system to read past valid memory, leading to the disclosure of sensitive kernel memory to userspace through the I2C/SMBus read path. This information disclosure could potentially expose confidential system data.
kernel: HID: mcp2221: validate report size in mcp2221_raw_event() — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.
Not affected:
Refer to the advisory for fix availability.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80958Medium· 5.5kernel: dm-pcache: clamp the tail kset read to the segment data region (CVE-2026-80958)
CVE-2026-80959Medium· 5.5kernel: dm-pcache: bound the persisted tail-position offset (CVE-2026-80959)
CVE-2026-80962Medium· 5.5kernel: dm-pcache: validate geometry fields from on-disk cache_info (CVE-2026-80962)
CVE-2026-89571Medium· 5.5kernel: cxl/features: bound fwctl command payload to the input buffer (CVE-2026-89571)
CVE-2026-89614Medium· 5.5kernel: ntfs: bound the free-cluster bitmap scan to the volume (CVE-2026-89614)
CVE-2026-89743Medium· 5.5kernel: misc: nsm: bound the device-reported response length (CVE-2026-89743)