CVE-2026-80918
Received Received - Intake

Type Confusion in Linux Kernel HID Core

Vulnerability report for CVE-2026-80918, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: HID: core: fix number/pointer type confusion on long items When fetch_item() is called by hid_scan_report() on an item with HID_ITEM_TAG_LONG, it stores a pointer to the item data in item->data.longdata instead of storing a value directly in item->data.{u8/u16/u32}. When item_udata() or item_sdata() encounters such an item, it incorrectly assumes that the item is in short format, and therefore returns the lower part of a kernel pointer reinterpreted as a number. When a HID device is connected whose descriptor contains a HID_GLOBAL_ITEM_TAG_REPORT_SIZE encoded in long format with size=4, this causes the lower half of a kernel pointer to be printed into dmesg as a number, like this: hid (null): invalid report_size 107953555 To fix it, let item_udata() and item_sdata() verify that the item is in short format. Note that this bug only affects hid_scan_report(), while the main parsing pass hid_parse_collections() will always bail out when encountering a long item. Sidenote: There are currently no users of data.longdata; maybe we should just remove any parsing of long-format descriptors as a follow-up.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a type confusion vulnerability in the Linux kernel's HID (Human Interface Device) core. When processing HID device descriptors with long-format items, the kernel incorrectly interprets kernel pointer data as a numeric value. This occurs because fetch_item() stores a pointer in item->data.longdata but item_udata() and item_sdata() assume short-format items, leading to pointer leakage in kernel logs.

Detection Guidance

This vulnerability is specific to the Linux kernel's HID subsystem and does not have network-based detection methods. It can be detected by checking kernel logs for messages like 'invalid report_size' followed by a number, which indicates the lower half of a kernel pointer being misinterpreted. Use the command 'dmesg | grep "invalid report_size"' to search for such messages.

Impact Analysis

This vulnerability could expose kernel memory addresses in system logs (dmesg) when a specific HID device with a malformed descriptor is connected. While it does not directly allow code execution, leaked pointers may aid attackers in bypassing security mechanisms like KASLR (Kernel Address Space Layout Randomization).

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it involves a kernel pointer leak in debug output during HID device scanning. It does not expose sensitive data or violate data protection requirements.

Mitigation Strategies

Immediately update your Linux kernel to the latest patched version provided by your distribution. If an update is not yet available, avoid connecting unknown or untrusted HID devices to the system until the patch is applied. Monitor kernel security advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80918. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart