« Volver al listado

CVE-2026-80782

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

HID: magicmouse: do not keep a stale msc->input if no input is claimed

magicmouse_input_mapping() caches the first hid_input's input_dev in msc->input while the report descriptor is parsed, and the rest of the driver treats a non-NULL msc->input as proof that an input device was registered.

That does not hold on the hid-input error path. If hidinput_connect() fails -- for instance because input_register_device() returns an error -- it unwinds through hidinput_disconnect(), which frees every input_dev it created, including the one cached in msc->input.

Leer descripción completaMostrar menos

The failure does not abort the probe. hid_connect() only skips the claim:

and the "device has no listeners" bailout below it does not fire for this driver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad 2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore returns 0 and magicmouse_probe() continues with msc->input pointing at freed memory. Being non-NULL, it passes the "input not registered" check in probe and the NULL checks in ->raw_event and ->event, so the next input report dereferences freed memory.

Clear msc->input when the HID core did not claim an input device, so the existing NULL checks cover this case as well.

Detalles técnicos trazas, registros y código del informe original
	if ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev,
				connect_mask & HID_CONNECT_HIDINPUT_FORCE))
		hdev->claimed |= HID_CLAIMED_INPUT;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80782",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "c3597923932bb90d4fc2186aef552f6677175e4a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "e0c224c93d10ee38854fdf24c815108aedd3dcb3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "3d7a7bac4c75f25b2513505a0ac5ba909588ed2b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "9bdf8c7bfd79f1090e61d28f969b32880fd77bb3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "15b60ade825c8ce9ec560048a4ae3747e4572be3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "0bf253e9ac994cb5329bc87b00bb4eeca9136791",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "2ef16934e069d5f771e989d6ee5c3ece5042f3cd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
              "lessThan": "0af3b89705688af01aa06025b84fa7a1e06ba6cc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0e55072e7c63a6569cab1447e9025d160abd9dd9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3.8.7",
              "lessThan": "3.9",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/hid/hid-magicmouse.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.269",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.218",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hid/hid-magicmouse.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:04.030",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: do not keep a stale msc->input if no input is claimed\n\nmagicmouse_input_mapping() caches the first hid_input's input_dev in\nmsc->input while the report descriptor is parsed, and the rest of the\ndriver treats a non-NULL msc->input as proof that an input device was\nregistered.\n\nThat does not hold on the hid-input error path. If hidinput_connect()\nfails -- for instance because input_register_device() returns an error --\nit unwinds through hidinput_disconnect(), which frees every input_dev it\ncreated, including the one cached in msc->input.\n\nThe failure does not abort the probe. hid_connect() only skips the claim:\n\n\tif ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev,\n\t\t\t\tconnect_mask & HID_CONNECT_HIDINPUT_FORCE))\n\t\thdev->claimed |= HID_CLAIMED_INPUT;\n\nand the \"device has no listeners\" bailout below it does not fire for this\ndriver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad\n2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore\nreturns 0 and magicmouse_probe() continues with msc->input pointing at\nfreed memory. Being non-NULL, it passes the \"input not registered\" check\nin probe and the NULL checks in ->raw_event and ->event, so the next\ninput report dereferences freed memory.\n\nClear msc->input when the HID core did not claim an input device, so the\nexisting NULL checks cover this case as well."
    }
  ],
  "lastModified": "2026-09-04T16:18:04.030",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}