CVE-2026-80918: HID: core: fix number/pointer type confusion on long items
HID: core: fix number/pointer type confusion on long items
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1
Event History
Frequently Asked Questions
What attacker-controlled input is required to trigger the issue?
A connected HID device must provide a descriptor containing a HID_GLOBAL_ITEM_TAG_REPORT_SIZE item encoded in long format with a size of 4. The issue is reached while the kernel scans that device's report descriptor.
Is the main HID descriptor parsing path affected?
No. The issue affects hid_scan_report(); the main parsing pass, hid_parse_collections(), bails out when it encounters a long item.
How might an affected system reveal the problem?
The kernel may print an invalid report_size value to dmesg, such as "hid (null): invalid report_size 107953555". That value can be the lower portion of a kernel pointer interpreted as a number.
What should be avoided until the fix is deployed?
Avoid connecting HID devices whose report descriptors contain long-format REPORT_SIZE items, particularly size-4 items. The supplied fix changes the item accessors so they verify that an item is in short format before interpreting its data as a numeric value.