CVE-2026-31401

Source
https://cve.org/CVERecord?id=CVE-2026-31401
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31401.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-31401
Downstream
Related
Published
2026-04-03T15:16:04.903Z
Modified
2026-07-15T01:48:55.198102545Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
HID: bpf: prevent buffer overflow in hid_hw_request
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: bpf: prevent buffer overflow in hidhwrequest

right now the returned value is considered to be always valid. However, when playing with HID-BPF, the return value can be arbitrary big, because it's the return value of dispatchhidbpfrawrequests(), which calls the struct_ops and we have no guarantees that the value makes sense.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31401.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8bd0488b5ea58655ad6fdcbe0408ef49b16882b1
Fixed
d6efaa50af62fb0790dd1fd4e7e5506b46312510
Fixed
73c5b5aea1c443239c8cb4191b4af7a4bd6fd7b1
Fixed
eb57dae20fdf6f3069cdc07821fa3bb46de381d7
Fixed
2b658c1c442ec1cd9eec5ead98d68662c40fe645

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31401.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.20
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31401.json"