CVE-2026-89627

Source
https://cve.org/CVERecord?id=CVE-2026-89627
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89627.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89627
Downstream
Published
2026-09-11T19:45:23Z
Modified
2026-09-13T03:47:20Z
Summary
HID: roccat: free buffered reports when destroying device
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: roccat: free buffered reports when destroying device

roccat_report_event() duplicates each report with kmemdup() and stores the allocation in a circular-buffer slot. The allocation is released only when that slot is reused.

The device destruction paths free struct roccat_device without releasing reports still stored in cbuf[]. This makes those allocations unreachable and leaks up to ROCCAT_CBUF_SIZE report buffers per device.

Add a small destructor that frees every buffered report before freeing the device, and use it in both paths that can destroy a registered device.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89627.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
206f5f2fcb5ff5bb0c60f9e9189937f3ca03e378
Fixed
943b8dc2c6044c01e36395f51bb809a4b6bdfd22
Fixed
da00eac19feef209c9591e48c860afc2014603be
Fixed
fbb5a60f5c31b5625f0d89a79912fbcb2559289b
Fixed
bbff0ccbff360a5498075525005f6a913239a3d7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89627.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.35
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89627.json"