CVE-2026-80780

    Dashboard / Vulnerabilities / CVE-2026-80780

    CVE-2026-80780

    Published: 4 Sept 2026Last Modified: 15 Sept 2026

    Summary: HID: pidff: fix OOB write when hid->inputs is empty

    Details: In the Linux kernel, the following vulnerability has been resolved: HID: pidff: fix OOB write when hid->inputs is empty hid_pidff_init_with_quirks() derives its input_dev from list_entry(hid->inputs.next, struct hid_input, list) without first checking that hid->inputs is non-empty. The list member of struct hid_input is at offset 0, so on an empty list list_entry() yields &hid->inputs itself and the following hidinput->input load reads an unrelated member of struct hid_device. dev is then a type-confused pointer, and force-feedback init writes through it: each set_bit(FF_*, dev->ffbit) stores 8 bytes at dev + 192, past the end of the object dev actually aliases, and input_ff_create() adds further writes of a heap pointer and two function pointers. Until hid-universal-pidff the only caller was hid_pidff_init() from usbhid, which runs under HID_CLAIMED_INPUT and therefore always has at least one hid_input. universal_pidff_probe() starts the device with HID_CONNECT_DEFAULT & ~HID_CONNECT_FF and then calls hid_pidff_init_with_quirks() directly whenever the descriptor carries a PID usage page, bypassing that gate. A report descriptor whose only application collection is on HID_UP_PID leaves hid->inputs empty while hid_connect() still succeeds through the hidraw claim, so probe reaches the unguarded list_entry(). The write happens in the USB probe path, on the hotplug workqueue, so plugging in a malicious device is enough to trigger it; no attacker software and no logged-in user are required. KASAN reports an 8-byte out-of-bounds write in hid_pidff_init_with_quirks() reached from universal_pidff_probe(). Check for an empty list before deriving dev and return -ENODEV, as the other HID force-feedback drivers already do. universal_pidff_probe() propagates the error and unwinds. Discovered by XBOW, triaged by Baul Lee <[email protected]>

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- c1fde337b317f0a226de92803288741c30799eb0

    Affected versions

    v6.6.155
    v6.6.154
    v6.6.153
    v6.6.152
    v6.6.151
    v6.6.150
    v6.6.149
    v6.6.148
    v6.6.147
    v6.6.146
    v6.6.145
    v6.6.144
    v6.6.143
    v6.6.142
    v6.6.141
    v6.6.140
    v6.6.139
    v6.6.138
    v6.6.137
    v6.6.136
    v6.6.135
    v6.6.134
    v6.6.133
    v6.6.132
    v6.6.131
    v6.6.130
    v6.6.129
    v6.6.128
    v6.6.127
    v6.6.126
    v6.6.125
    v6.6.124
    v6.6.123
    v6.6.122
    v6.6.121
    v6.6.120
    v6.6.119
    v6.6.118
    v6.6.117
    v6.6.116
    v6.6.115
    v6.6.114
    v6.6.113
    v6.6.112
    v6.6.111
    v6.6.110
    v6.6.109
    v6.6.108
    v6.6.107
    v6.6.106
    v6.6.105
    v6.6.104
    v6.6.103
    v6.6.102
    v6.6.101
    v6.6.100
    v6.6.99
    v6.6.98
    v6.6.97
    v6.6.96
    v6.6.95
    v6.6.94
    v6.6.93
    v6.6.92
    v6.6.91
    v6.6.90
    v6.6.89
    v6.6.88
    v6.6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-80780 | CVE-DB