CVE-2026-31401
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/04/2026
Last modified:
03/04/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
HID: bpf: prevent buffer overflow in hid_hw_request<br />
<br />
right now the returned value is considered to be always valid. However,<br />
when playing with HID-BPF, the return value can be arbitrary big,<br />
because it&#39;s the return value of dispatch_hid_bpf_raw_requests(), which<br />
calls the struct_ops and we have no guarantees that the value makes<br />
sense.



