SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-80769

UNKNOWN · CVSS N/A EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-19

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of HID devices, specifically in the `to_usb_interface()` function, which can incorrectly process non-USB HID devices as if they were USB. This flaw can lead to a kernel crash, or "splat," when triggered, potentially causing system instability. Organizations utilizing Linux systems with HID devices should prioritize this fix to ensure kernel stability and prevent potential disruptions.

CVE
CVE-2026-80769
Severity
UNKNOWN
CVSS
N/A
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: HID: rapoo: fix missing hid_is_usb() check to_usb_interface() can only be used on a hid_device whose parent is really USB; uhid can create devices that identify as being on BUS_USB, but don't actually have a USB parent. Fix the use of to_usb_interface() without a hid_is_usb() check. Add a dependency on USB_HID for hid_is_usb(), as other HID drivers do; the alternative would be to provide a simple stub implementation on !USB_HID builds. I have verified that it is currently possible to trigger a kernel splat due to this bug in an ASAN build, and that this commit fixes the issue.