Description
In the Linux kernel, the following vulnerability has been resolved:

HID: roccat: free buffered reports when destroying device

roccat_report_event() duplicates each report with kmemdup() and stores
the allocation in a circular-buffer slot. The allocation is released only
when that slot is reused.

The device destruction paths free struct roccat_device without releasing
reports still stored in cbuf[]. This makes those allocations unreachable
and leaks up to ROCCAT_CBUF_SIZE report buffers per device.

Add a small destructor that frees every buffered report before freeing the
device, and use it in both paths that can destroy a registered device.
Published: 2026-09-11
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Memory Exhaustion)
Action: Apply Patch
AI Analysis

Impact

The roccat HID driver in the Linux kernel copies each incoming report with kmemdup() and stores the duplicate in a circular buffer slot. The allocation is released only when that slot is reused. When a roccat device is destroyed, the driver frees the device structure but leaves the duplicated reports stored in the buffer unreleased, creating a memory leak that may accumulate up to ROCCAT_CBUF_SIZE buffers per device. This results in increased heap usage that can exhaust system memory and degrade performance, constituting a denial‑of‑service condition. The flaw is a classic example of improper resource release (CWE‑772).

Affected Systems

Linux kernel distributions that include the roccat HID driver before the destructor fix are affected. Because the vendor information lists generic Linux kernels, the vulnerability may be present in any kernel branch that bundles the roccat driver without the patch. Administrators should determine whether their kernel version incorporates the fix; up‑to‑date kernels normally contain the constructor added in the patch series referenced in the provided commits.

Risk and Exploitability

The CVSS score of 3.3 and an EPSS score of less than 1% indicate low severity and a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. According to the description, an attacker must trigger the destruction of a roccat device, which generally requires privileged or local access to the device. Thus the attack vector is likely local privileged access, and the overall risk is confined to environments where such capabilities are possible. Even if exploited, the impact is limited to memory exhaustion rather than full system compromise.

Generated by OpenCVE AI on September 15, 2026 at 21:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel release that includes the roccat HID destructor fix for buffered reports.
  • If the roccat HID driver is unnecessary, disable or remove it from the kernel configuration to prevent this memory leak.
  • Monitor system memory usage for abnormal growth that correlates with HID device activity to detect and remediate persistent leaks.

Generated by OpenCVE AI on September 15, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Low


Sat, 12 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: roccat: free buffered reports when destroying device roccat_report_event() duplicates each report with kmemdup() and stores the allocation in a circular-buffer slot. The allocation is released only when that slot is reused. The device destruction paths free struct roccat_device without releasing reports still stored in cbuf[]. This makes those allocations unreachable and leaks up to ROCCAT_CBUF_SIZE report buffers per device. Add a small destructor that frees every buffered report before freeing the device, and use it in both paths that can destroy a registered device.
Title HID: roccat: free buffered reports when destroying device
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:38.515Z

Reserved: 2026-09-11T19:38:34.738Z

Link: CVE-2026-89627

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:48.153

Modified: 2026-09-14T13:19:16.377

Link: CVE-2026-89627

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T19:45:23Z

Links: CVE-2026-89627 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime