CVE-2026-89729High· 7.0▾ TwilightA flaw was found in the Linux kernel's Human Interface Device (HID) sensor-hub driver. A local attacker could exploit this vulnerability by providing a specially crafted HID descriptor. This malicious descriptor could cause the `sensor_hub…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6.3
none → medium
— → 6.3
none → medium
— → 8.8
none → high
8.8 → 6.3
high → medium
6.3 → 8.8
medium → high
0.2% → 0.4%
Last analysed / modified upstream
8.8 → 7
A flaw was found in the Linux kernel's Human Interface Device (HID) sensor-hub driver. A local attacker could exploit this vulnerability by providing a specially crafted HID descriptor. This malicious descriptor could cause the sensor_hub_get_feature() function to write data beyond the intended memory buffer. This out-of-bounds write could lead to a system crash (denial of service) or potentially allow for arbitrary code execution, compromising the system's integrity.
kernel: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.
Affected:
No fix planned:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89436Medium· 5.5kernel: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] (CVE-2026-89436)
CVE-2026-89513Medium· 5.5kernel: RISC-V: KVM: Fix PMU event info array size overflow (CVE-2026-89513)
CVE-2026-89610Medium· 5.5kernel: ntfs: verify run length exceeding volume boundary (CVE-2026-89610)
CVE-2026-89611Medium· 5.5kernel: ntfs: validate non-resident attribute offsets (CVE-2026-89611)
CVE-2026-89612Medium· 5.5kernel: ntfs: reject invalid MFT LCNs from boot sector (CVE-2026-89612)
CVE-2026-89748Medium· 5.5kernel: tracing: Fix retry exhaustion in simple ring buffer reader swap (CVE-2026-89748)