CVE-2026-43140

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: Do not crash on missing msc->input Fake USB devices can send their own report descriptors for which the input_mapping() hook does not get called. In this case, msc->input stays NULL, leading to a crash at a later time. Detect this condition in the input_configured() hook and reject the device. This is not supposed to happen with actual magic mouse devices, but can be provoked by imposing as a magic mouse USB device.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

13 May 2026, 20:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
CWE CWE-476
References () https://git.kernel.org/stable/c/165912d4321c692321c02793068d30700b4e0f1a - () https://git.kernel.org/stable/c/165912d4321c692321c02793068d30700b4e0f1a - Patch
References () https://git.kernel.org/stable/c/17abd396548035fbd6179ee1a431bd75d49676a7 - () https://git.kernel.org/stable/c/17abd396548035fbd6179ee1a431bd75d49676a7 - Patch
References () https://git.kernel.org/stable/c/243e1165eb03aca97d87aafa9c3130593837a1c2 - () https://git.kernel.org/stable/c/243e1165eb03aca97d87aafa9c3130593837a1c2 - Patch
References () https://git.kernel.org/stable/c/36c83c1329dd881f290f7df2feadfb9a21775108 - () https://git.kernel.org/stable/c/36c83c1329dd881f290f7df2feadfb9a21775108 - Patch
References () https://git.kernel.org/stable/c/5bbe266272d86c0657e8253600f3d5b74fb7b2ae - () https://git.kernel.org/stable/c/5bbe266272d86c0657e8253600f3d5b74fb7b2ae - Patch
References () https://git.kernel.org/stable/c/922bd3e498a4b8e445def6e6ffea2ad3682ad516 - () https://git.kernel.org/stable/c/922bd3e498a4b8e445def6e6ffea2ad3682ad516 - Patch
References () https://git.kernel.org/stable/c/db5ba06e7af9325519a03e52fccf4a9e7c1fd9b2 - () https://git.kernel.org/stable/c/db5ba06e7af9325519a03e52fccf4a9e7c1fd9b2 - Patch
References () https://git.kernel.org/stable/c/f6a3860241fbb556fd72332fa31c5e787004413b - () https://git.kernel.org/stable/c/f6a3860241fbb556fd72332fa31c5e787004413b - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

06 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 12:16

Updated : 2026-05-13 20:56


NVD link : CVE-2026-43140

Mitre link : CVE-2026-43140

CVE.ORG link : CVE-2026-43140


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference