Vulnerability Bulletins

CVE-2026-43251

   
Affected software LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

HID: prodikeys: Check presence of pm->input_ep82

Fake USB devices can send their own report descriptors for which the
input_mapping() hook does not get called. In this case, pm->input_ep82 stays
NULL, which leads to a crash later.

This does not happen with the real device, but can be provoked by imposing as
one.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-43251