In the Linux kernel, the following vulnerability has been resolved:
HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()
Do not crash when a report has no fields.
Fake USB gadgets can send their own HID report descriptors and can define report
structures without valid fields. This can be used to crash the kernel over USB.
References
Configurations
Configuration 1 (hide)
|
History
12 May 2026, 21:14
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| References | () https://git.kernel.org/stable/c/1547d41f9f19d691c2c9ce4c29f746297baef9e9 - Patch | |
| References | () https://git.kernel.org/stable/c/1acb28123e57b50d737377f400f57eec889fe5e4 - Patch | |
| References | () https://git.kernel.org/stable/c/2dc023dbc11b8dfa8afa63242762acd8cddcad03 - Patch | |
| References | () https://git.kernel.org/stable/c/7f59999fcd699af06ad2aef446a635ea6aa87db3 - Patch | |
| References | () https://git.kernel.org/stable/c/ae81fac9ce81917817d787e6b74e68482d99bdf2 - Patch | |
| References | () https://git.kernel.org/stable/c/b74bf7d0d01fa9b53653f58c29aa00772121f6e9 - Patch | |
| References | () https://git.kernel.org/stable/c/f1ceaaf93ea32d0f2b95c95f784ee155962c52ad - Patch | |
| References | () https://git.kernel.org/stable/c/fb1725c0804dbec9dd01c4cb5c9f1f77a69e36dc - Patch | |
| CWE | NVD-CWE-noinfo | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| First Time |
Linux linux Kernel
Linux |
06 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-06 12:16
Updated : 2026-05-12 21:14
NVD link : CVE-2026-43136
Mitre link : CVE-2026-43136
CVE.ORG link : CVE-2026-43136
JSON object : View
Products Affected
linux
- linux_kernel
CWE
