CVE-2026-89621

Source
https://cve.org/CVERecord?id=CVE-2026-89621
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89621.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89621
Downstream
Published
2026-09-11T19:45:19Z
Modified
2026-09-13T03:47:19Z
Summary
HID: mcp2221: validate report size in mcp2221_raw_event()
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: mcp2221: validate report size in mcp2221_raw_event()

mcp2221_raw_event() never validates the size of incoming HID reports. In the MCP2221_I2C_GET_DATA path it trusts the device-supplied data[3] as the copy length without checking that 4 + data[3] bytes actually exist in the received report. A malicious or misbehaving USB device can send a short report with a large data[3], causing the memcpy to read past the valid report data in the HID transfer buffer and leak uninitialized kernel memory back to userspace through the I2C/SMBus read path.

Add a minimum size check at entry and validate that the source range fits within the received report before the copy.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89621.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
67a95c21463d066060b0f66d65a75d45bb386ffb
Fixed
bdc6a3af0dd734a326acdb7d6401a3b6a9f4f149
Fixed
127de5919820f88a9d55e8371ad4ac49f625f4c5
Fixed
7c18fb36708a97ff6772825cc087b6d537bbf0d5
Fixed
2c9a6998c19503626c57a2267bf279e204113079

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89621.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89621.json"