CVE-2026-31524: HID: asus: avoid memory leak in asus_report_fixup()
HID: asus: avoid memory leak in asusreportfixup()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.134.1-2 - Compensating control
In the Linux kernel HID ASUS driver, update asus_report_fixup() to use devm_kzalloc() so allocated memory is freed automatically when the device is removed, and copy only the original descriptor size to avoid the out-of-bounds read.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31524?
CVE-2026-31524 is classified as a medium severity vulnerability due to its potential to cause a memory leak in the Linux kernel.
How do I fix CVE-2026-31524?
To fix CVE-2026-31524, you should apply the latest patch from the Linux kernel maintainers that addresses the memory leak in the asus_report_fixup() function.
What systems are affected by CVE-2026-31524?
CVE-2026-31524 affects the Linux kernel specifically in the HID: asus module.
What impact does CVE-2026-31524 have on my system?
The impact of CVE-2026-31524 includes potential system instability or performance degradation due to memory leaks.
Is there a workaround for CVE-2026-31524?
Currently, there are no known workarounds for CVE-2026-31524, so updating to the patched version is recommended.