SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-80767

UNKNOWN · CVSS N/A EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-19

CyberRota Analysis

AI-Generated

A use-after-free vulnerability exists in the Linux kernel's HID sensor subsystem, specifically within the enable_sensor function, which can lead to dereferencing freed memory. This flaw may allow an attacker to exploit the system by manipulating sensor states, potentially leading to system instability or unauthorized access. Organizations utilizing Linux-based systems, particularly those relying on HID sensors, should prioritize patching to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-80767
Severity
UNKNOWN
CVSS
N/A
EPSS
0.19%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix use-after-free in enable_sensor enable_sensor_store() can call set_power_report_state(), which dereferences sensor_inst->power_state and sensor_inst->report_state. These pointers refer to entries in sensor_inst->fields. Create the field attributes before exposing the enable_sensor sysfs attribute, so enable_sensor cannot be accessed before the state it depends on has been initialized. On remove, delete enable_sensor before freeing the field attributes, so a concurrent sysfs write cannot dereference freed memory through power_state or report_state.