Answer in brief
CVE-2026-72078 records a Unknown severity vulnerability in Input: ims-pcu - validate control endpoint type. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72078 records a Unknown severity vulnerability in Input: ims-pcu - validate control endpoint type. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=628329d52474323938a03826941e166bc7c8eff4 <5de5075a1f26166f172b6687cb66810a9b61e3eb || >=628329d52474323938a03826941e166bc7c8eff4 <7960d99332e03705ec622d92f31e0c77de8baac6 || >=628329d52474323938a03826941e166bc7c8eff4 <5b96b4da96313dd799a3a40dcfd598d2e2c19217 || >=628329d52474323938a03826941e166bc7c8eff4 <aa1885f87e60c80e59e50ffd5fb096bf02c83e05 || >=628329d52474323938a03826941e166bc7c8eff4 <a630508a09b0c05f14bc0843ed409221a93751aa || >=628329d52474323938a03826941e166bc7c8eff4 <c8d3d83f2eaaf7659de76e8d44e8fc88ee346042 || >=628329d52474323938a03826941e166bc7c8eff4 <cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e || >=628329d52474323938a03826941e166bc7c8eff4 <baf56975806534268e24acf9a8abb1c447ce11e9 | 5de5075a1f26166f172b6687cb66810a9b61e3eb, 7960d99332e03705ec622d92f31e0c77de8baac6, 5b96b4da96313dd799a3a40dcfd598d2e2c19217, aa1885f87e60c80e59e50ffd5fb096bf02c83e05, a630508a09b0c05f14bc0843ed409221a93751aa, c8d3d83f2eaaf7659de76e8d44e8fc88ee346042, cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e, baf56975806534268e24acf9a8abb1c447ce11e9 |
| Linux/Linuxgeneric | 3.10 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - validate control endpoint type The driver currently assumes that the first endpoint of the control interface is an interrupt IN endpoint without verifying it. A malicious device could provide a different endpoint type, which would then be passed to usb_fill_int_urb(), potentially leading to kernel warnings or undefined behavior. Verify that the control endpoint is an interrupt IN endpoint.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=628329d52474323938a03826941e166bc7c8eff4 <5de5075a1f26166f172b6687cb66810a9b61e3eb || >=628329d52474323938a03826941e166bc7c8eff4 <7960d99332e03705ec622d92f31e0c77de8baac6 || >=628329d52474323938a03826941e166bc7c8eff4 <5b96b4da96313dd799a3a40dcfd598d2e2c19217 || >=628329d52474323938a03826941e166bc7c8eff4 <aa1885f87e60c80e59e50ffd5fb096bf02c83e05 || >=628329d52474323938a03826941e166bc7c8eff4 <a630508a09b0c05f14bc0843ed409221a93751aa || >=628329d52474323938a03826941e166bc7c8eff4 <c8d3d83f2eaaf7659de76e8d44e8fc88ee346042 || >=628329d52474323938a03826941e166bc7c8eff4 <cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e || >=628329d52474323938a03826941e166bc7c8eff4 <baf56975806534268e24acf9a8abb1c447ce11e9 | 5de5075a1f26166f172b6687cb66810a9b61e3eb, 7960d99332e03705ec622d92f31e0c77de8baac6, 5b96b4da96313dd799a3a40dcfd598d2e2c19217, aa1885f87e60c80e59e50ffd5fb096bf02c83e05, a630508a09b0c05f14bc0843ed409221a93751aa, c8d3d83f2eaaf7659de76e8d44e8fc88ee346042, cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e, baf56975806534268e24acf9a8abb1c447ce11e9 |
| Linux/Linuxgeneric | 3.10 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - validate control endpoint type The driver currently assumes that the first endpoint of the control interface is an interrupt IN endpoint without verifying it. A malicious device could provide a different endpoint type, which would then be passed to usb_fill_int_urb(), potentially leading to kernel warnings or undefined behavior. Verify that the control endpoint is an interrupt IN endpoint.
Quoted source text, attributed separately from HOL analysis.