Answer in brief
CVE-2026-80605 records a Unknown severity vulnerability in HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <42dc0b7b55fe0499fc09183f34a1c46d1dcccf77 || >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <48caee2c106b03301c72fe389ebff00d852c58d5 || >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <dc176447c7279435c46735db7da81aed1ec25cc2 || >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <a02d5d7ad7ae5fa3756b8332f7350e973085dcb3 || >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <e4edeefb8d5bfceb2058e2b3291f4ae1e5a76e61 || >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <d354e523c6f740db758cafcd4c11bb7913285ed8 || >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <ef649703dce0df1364fcec3cdad9b32d1c522939 || >=fabdbf2fd22fa170b4c5340dbdda5c8cd88fb205 <0021eb09041f021c079be1022934a280f7f176c0 | 42dc0b7b55fe0499fc09183f34a1c46d1dcccf77, 48caee2c106b03301c72fe389ebff00d852c58d5, dc176447c7279435c46735db7da81aed1ec25cc2, a02d5d7ad7ae5fa3756b8332f7350e973085dcb3, e4edeefb8d5bfceb2058e2b3291f4ae1e5a76e61, d354e523c6f740db758cafcd4c11bb7913285ed8, ef649703dce0df1364fcec3cdad9b32d1c522939, 0021eb09041f021c079be1022934a280f7f176c0 |
| Linux/Linuxgeneric | 3.7 | Not reported |
Published upstream
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
In the Linux kernel, the following vulnerability has been resolved: HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() In picolcd_send_and_wait(), an integer overflow of the signed loop counter 'k' can theoretically lead to a NULL pointer dereference of 'raw_data'. If the loop executes more than INT_MAX times, 'k' becomes negative, making the condition 'k < size' true even when 'size' is 0. Change the type of 'k' to 'unsigned int' to prevent the overflow and eliminate the out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with the Svace static analysis tool. [[email protected]: extended hash length]
Quoted source text, attributed separately from HOL analysis.