-
CVE-2026-80769
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:12:41
- Zuletzt bearbeitet 04.09.2026 16:18:02
- Erkennungen
HID: rapoo: fix missing hid_is_usb() check
In the Linux kernel, the following vulnerability has been resolved: HID: rapoo: fix missing hid_is_usb() check to_usb_interface() can only be used on a hid_device whose parent is really USB; uhid can create devices that identify as being on BUS_USB, but don't actually have a USB parent. Fix the use of to_usb_interface() without a hid_is_usb() check. Add a dependency on USB_HID for hid_is_usb(), as other HID drivers do; the alternative would be to provide a simple stub implementation on !USB_HID builds. I have verified that it is currently possible to trigger a kernel splat due to this bug in an ASAN build, and that this commit fixes the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
b3b1c68fb726907ea35ac172906705fe62c7fdaf
Version <
99ed3febafe0452994620a4d819f595583289bec
Status
affected
Version
b3b1c68fb726907ea35ac172906705fe62c7fdaf
Version <
49b6fd28fbcc0b6457e16e25c7617f63449d4808
Status
affected
Version
b3b1c68fb726907ea35ac172906705fe62c7fdaf
Version <
b57af2448268c30c25509a832b6ff6dc27176b28
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.0
Status
affected
Version
0
Version <
7.0
Status
unaffected
Version <=
7.1.*
Version
7.1.11
Status
unaffected
Version <=
7.2.*
Version
7.2.1
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/99ed3febafe0452994620a4d819f595583289bec
https://git.kernel.org/stable/c/49b6fd28fbcc0b6457e16e25c7617f63449d4808
https://git.kernel.org/stable/c/b57af2448268c30c25509a832b6ff6dc27176b28