Description
In the Linux kernel, the following vulnerability has been resolved:

HID: corsair-void: Check size of status and firmware events before reading them

Malformed status and firmware events could cause an out-of-bounds read since
the size wasn't being checked. Check the size and warn on unexpected values to
avoid this.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service
Action: Patch
AI Analysis

Impact

The flaw is in the HID subsystem that handles Corsair devices in the Linux kernel. The driver does not check the size of status and firmware events before reading them, which allows an attacker to send malformed events that trigger an out‑of‑bounds read. effectively denying local services. The weakness as CWE-125.

Affected Systems

The vulnerability affects the core Linux kernel and therefore all distributions built on it that have not incorporated the patch commits 0329354abba3, 08d8814521, or 79465a3005. No specific kernel release numbers are listed, so any kernel without those changes is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity, while the EPSS score of less than 1% shows a very low likelihood of active exploitation. The flaw is not listed in the CISA KEV catalog. An attacker would need local physical or logical access to a Corsair HID device to inject malformed events and trigger the out‑of‑bounds read, denial of service. The attack vector is therefore inferred to be local device interaction.

Generated by OpenCVE AI on September 15, 2026 at 21:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the HID size‑check patch or apply commits 0329354abba3, 08d8814521, and 79465a3005 to the source.
  • If an immediate kernel update is not possible, disable or block the Corsair HID device through a module blacklist or udev rule.
  • Reboot the system after applying the updated kernel changes or device restrictions to ensure the protection takes effect.

Generated by OpenCVE AI on September 15, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Check size of status and firmware events before reading them Malformed status and firmware events could cause an out-of-bounds read since the size wasn't being checked. Check the size and warn on unexpected values to avoid this.
Title HID: corsair-void: Check size of status and firmware events before reading them
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:45:24.953Z

Reserved: 2026-09-11T19:38:34.738Z

Link: CVE-2026-89629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:48.400

Modified: 2026-09-11T20:19:48.400

Link: CVE-2026-89629

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:24Z

Links: CVE-2026-89629 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses