CVE-2026-45877: HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
Published May 27, 2026
·Updated
HID: intel-ish-hid: fix NULL-ptr-deref in ishtpbusremoveallclients
Affected Software
4 affected components
Intel intel_ishtp (intel-ish-hid)
Linux Linux kernel>=4.9<6.12.75
Linux Linux kernel>=6.13<6.18.14
Linux Linux kernel>=6.19<6.19.4
Event History
May 27, 2026
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
Description
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 28, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-45877?
The severity of CVE-2026-45877 is rated as 27.
2
How do I fix CVE-2026-45877?
To fix CVE-2026-45877, update the Linux kernel to the latest version that addresses this NULL pointer dereference issue.
3
What component is affected by CVE-2026-45877?
CVE-2026-45877 affects the Intel intel_ishtp (intel-ish-hid) component within the Linux kernel.
4
What type of vulnerability is CVE-2026-45877?
CVE-2026-45877 is a NULL pointer dereference vulnerability that can occur during the warm reset flow.
5
When was CVE-2026-45877 published?
CVE-2026-45877 was published on May 27, 2026.