CVE-2026-43048: HID: core: Mitigate potential OOB by removing bogus memset()
In the Linux kernel, the following vulnerability has been resolved:
HID: core: Mitigate potential OOB by removing bogus memset()
The memset() in hidreportrawevent() has the good intention of clearing out bogus data by zeroing the area from the end of the incoming data string to the assumed end of the buffer. However, as we have previously seen, doing so can easily result in OOB reads and writes in the subsequent thread of execution.
The current suggestion from one of the HID maintainers is to remove the memset() and simply return if the incoming event buffer size is not large enough to fill the associated report.
Suggested-by Benjamin Tissoires <bentiss@kernel.org>
[bentiss: changed the return value]
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In hid_report_raw_event(), remove the memset() that zeroes the area from the end of the incoming data string to the assumed end of the buffer; instead, if the incoming event buffer size is not previously seen, simply return to avoid potential OOB reads/writes in subsequent thread execution.
Linux kernel HID (hid_report_raw_event) memset() removal = remove memset() and return if incoming event buffer size is not previously seen
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43048?
CVE-2026-43048 is rated as a medium severity vulnerability.
How do I fix CVE-2026-43048?
To fix CVE-2026-43048, update your Linux kernel to the latest stable version where this vulnerability has been addressed.
What does CVE-2026-43048 affect?
CVE-2026-43048 affects the HID core component of the Linux kernel.
What is the impact of CVE-2026-43048?
The impact of CVE-2026-43048 includes possible out-of-bounds access due to a bug in the memset() function.
Is CVE-2026-43048 actively exploited?
As of now, there are no reports indicating that CVE-2026-43048 is actively exploited in the wild.