Answer in brief
CVE-2026-80765 records a Unknown severity vulnerability in HID: hyperv: validate initial device info bounds. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b95f5bcb811e3905b5376f87789da8d097fee682 <e0d5d3e45e142b7ef7525654aaa54d3e986002a6 || >=b95f5bcb811e3905b5376f87789da8d097fee682 <390d3d9c52a710fdc9de95a537747397c0c671d1 || >=b95f5bcb811e3905b5376f87789da8d097fee682 <8614c043b11cc35ffebd35542ab4da275f8f923d || >=b95f5bcb811e3905b5376f87789da8d097fee682 <334271d3812ab3197c95b4593bc6745f8d189114 || >=b95f5bcb811e3905b5376f87789da8d097fee682 <f84d777574b748b1a488723ca7be9d87a301a872 || >=b95f5bcb811e3905b5376f87789da8d097fee682 <608f8fd8c0f7b6268da43509447802955f210aac || >=b95f5bcb811e3905b5376f87789da8d097fee682 <2529737763cb4bcfcaf397beeea2664656c865b4 || >=b95f5bcb811e3905b5376f87789da8d097fee682 <c894143c508a7e063aab9f73c9e835ab40121283 || >=b95f5bcb811e3905b5376f87789da8d097fee682 <934b7778aa7b7c8f6bb073d2a73ba3674885bae0 | e0d5d3e45e142b7ef7525654aaa54d3e986002a6, 390d3d9c52a710fdc9de95a537747397c0c671d1, 8614c043b11cc35ffebd35542ab4da275f8f923d, 334271d3812ab3197c95b4593bc6745f8d189114, f84d777574b748b1a488723ca7be9d87a301a872, 608f8fd8c0f7b6268da43509447802955f210aac, 2529737763cb4bcfcaf397beeea2664656c865b4, c894143c508a7e063aab9f73c9e835ab40121283, 934b7778aa7b7c8f6bb073d2a73ba3674885bae0 |
| Linux/Linuxgeneric | 3.3 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: HID: hyperv: validate initial device info bounds The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descriptor followed by the report descriptor bytes. mousevsc_on_receive_device_info() trusts bLength and wDescriptorLength without checking that the received packet contains both byte ranges. A malformed host or backend message can therefore make the guest read past the received VMBus packet while copying the report descriptor. Pass the received initial-device-info size into the parser and reject descriptor lengths that exceed the packet. Impact: A malicious Hyper-V host or backend can crash a guest by sending a short initial device-info message with an oversized HID report descriptor length.
Quoted source text, attributed separately from HOL analysis.