news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-43136

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.5 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.13%
Risk score
1.5
Published
2026-05-06
Status
Published

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Check maxfield in hidpp_get_report_length() Do not crash when a report has no fields. Fake USB gadgets can send their own HID report descriptors and can define report structures without valid fields. This can be used to crash the kernel over USB. A flaw was found in the Linux kernel's Human Interface Device (HID) subsystem, specifically within the logitech-hidpp driver. A remote attacker, by connecting a specially crafted Universal Serial Bus (USB) device, could send malformed HID report descriptors that lack valid fields. This could lead to a kernel crash, resulting in a Denial of Service (DoS) for the affected system.

Weaknesses

CWE-166

Coverage 6

Advisories and references