In the Linux kernel, the following vulnerability has been resolved:
HID: core: Fix OOB read in hidgetreport for numbered reports
When a caller passes a size of 0 to hidreportrawevent() for a numbered report, the function originally called hidget_report() before performing any size validation.
Inside hidgetreport(), if the report is numbered (report_enum->numbered is true), it unconditionally dereferences data[0] to extract the report ID. With a size of 0, this results in an out-of-bounds read or kernel panic.
Fix this by moving the numbered report size validation check before the call to hidgetreport(), ensuring that size is at least 1 before dereferencing the data pointer.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80604.json",
"cna_assigner": "Linux"
}