Answer in brief
CVE-2026-80573 records a Unknown severity vulnerability in Input: iforce - validate input packet lengths. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <0ec411167655ef3ff3e84f6af685e962aff9a75b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <609be40988898a4d75225ade0ea5c1734757dd33 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e73d7a7d913d89141321f5f3f16343ecc200d152 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5232529eaf57f08fe37484e301579a1915b93d14 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2c083ab16e33fbff3ab8c752fbf8118ed3dd31ce || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <a64a8b6b31cd669f0449138e53cc2592d454ccf1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <84e5cb517f445dadbd5f8bf4ec513540e51f9c36 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5751c781d3c97ab6ce0e2a966156ed882152c415 || >=0 <5.10.266 || >=0 <5.15.217 || >=0 <6.1.184 || >=0 <6.6.153 || >=0 <6.12.105 || >=0 <6.18.46 || >=0 <7.1.10 | 0ec411167655ef3ff3e84f6af685e962aff9a75b, 609be40988898a4d75225ade0ea5c1734757dd33, e73d7a7d913d89141321f5f3f16343ecc200d152, 5232529eaf57f08fe37484e301579a1915b93d14, 2c083ab16e33fbff3ab8c752fbf8118ed3dd31ce, a64a8b6b31cd669f0449138e53cc2592d454ccf1, 84e5cb517f445dadbd5f8bf4ec513540e51f9c36, 5751c781d3c97ab6ce0e2a966156ed882152c415, 5.10.266, 5.15.217, 6.1.184, 6.6.153, 6.12.105, 6.18.46, 7.1.10 |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - validate input packet lengths iforce_process_packet() reads fixed fields from joystick, wheel and status packets without first checking their lengths. In particular, the shared hats-and-buttons helper unconditionally reads data[6]. The status tail is a sequence of 16-bit effect addresses, but an incomplete final address is also consumed. A successful zero-length USB URB additionally reads the packet ID before the common parser is called. Reject the zero-length USB transfer, require the seven-byte joystick and wheel prefixes and the two-byte status prefix, and consume only complete status-tail addresses.
Quoted source text, attributed separately from HOL analysis.