PT-2026-36465 · Linux · Linux Kernel

Benjamin Tissoires

+1

·

Published

2026-05-01

·

Updated

2026-05-22

·

CVE-2026-43048

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the HID core where the memset() function within hid report raw event() attempts to clear data by zeroing the area between the end of the incoming data string and the assumed end of the buffer. This operation can lead to out-of-bounds (OOB) reads and writes—where the system accesses memory outside the intended boundary—in the subsequent thread of execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-43048
OESA-2026-2415
OESA-2026-2416
OESA-2026-2417
OESA-2026-2418
OESA-2026-2419

Affected Products

Linux Kernel