CVE-2026-80782
In the Linux kernel, the following vulnerability has been resolved:
HID: magicmouse: do not keep a stale msc->input if no input is claimed
magicmouse_input_mapping() caches the first hid_input's input_dev in msc->input while the report descriptor is parsed, and the rest of the driver treats a non-NULL msc->input as proof that an input device was registered.
That does not hold on the hid-input error path. If hidinput_connect() fails -- for instance because input_register_device() returns an error -- it unwinds through hidinput_disconnect(), which frees every input_dev it created, including the one cached in msc->input.
Leer descripción completaMostrar menos
The failure does not abort the probe. hid_connect() only skips the claim:
and the "device has no listeners" bailout below it does not fire for this driver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad 2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore returns 0 and magicmouse_probe() continues with msc->input pointing at freed memory. Being non-NULL, it passes the "input not registered" check in probe and the NULL checks in ->raw_event and ->event, so the next input report dereferences freed memory.
Clear msc->input when the HID core did not claim an input device, so the existing NULL checks cover this case as well.
Detalles técnicos trazas, registros y código del informe original
if ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev, connect_mask & HID_CONNECT_HIDINPUT_FORCE)) hdev->claimed |= HID_CLAIMED_INPUT;
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc
- https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791
- https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3
- https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd
- https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b
- https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14
- https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3
- https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a
- https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80782",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "c3597923932bb90d4fc2186aef552f6677175e4a",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "e0c224c93d10ee38854fdf24c815108aedd3dcb3",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "3d7a7bac4c75f25b2513505a0ac5ba909588ed2b",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "9bdf8c7bfd79f1090e61d28f969b32880fd77bb3",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "15b60ade825c8ce9ec560048a4ae3747e4572be3",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "0bf253e9ac994cb5329bc87b00bb4eeca9136791",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "2ef16934e069d5f771e989d6ee5c3ece5042f3cd",
"versionType": "git"
},
{
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"lessThan": "0af3b89705688af01aa06025b84fa7a1e06ba6cc",
"versionType": "git"
},
{
"status": "affected",
"version": "0e55072e7c63a6569cab1447e9025d160abd9dd9",
"versionType": "git"
},
{
"status": "affected",
"version": "3.8.7",
"lessThan": "3.9",
"versionType": "semver"
}
],
"programFiles": [
"drivers/hid/hid-magicmouse.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/hid/hid-magicmouse.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T16:18:04.030",
"references": [
{
"url": "https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: do not keep a stale msc->input if no input is claimed\n\nmagicmouse_input_mapping() caches the first hid_input's input_dev in\nmsc->input while the report descriptor is parsed, and the rest of the\ndriver treats a non-NULL msc->input as proof that an input device was\nregistered.\n\nThat does not hold on the hid-input error path. If hidinput_connect()\nfails -- for instance because input_register_device() returns an error --\nit unwinds through hidinput_disconnect(), which frees every input_dev it\ncreated, including the one cached in msc->input.\n\nThe failure does not abort the probe. hid_connect() only skips the claim:\n\n\tif ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev,\n\t\t\t\tconnect_mask & HID_CONNECT_HIDINPUT_FORCE))\n\t\thdev->claimed |= HID_CLAIMED_INPUT;\n\nand the \"device has no listeners\" bailout below it does not fire for this\ndriver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad\n2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore\nreturns 0 and magicmouse_probe() continues with msc->input pointing at\nfreed memory. Being non-NULL, it passes the \"input not registered\" check\nin probe and the NULL checks in ->raw_event and ->event, so the next\ninput report dereferences freed memory.\n\nClear msc->input when the HID core did not claim an input device, so the\nexisting NULL checks cover this case as well."
}
],
"lastModified": "2026-09-04T16:18:04.030",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}