Answer in brief
CVE-2026-89729 records a Unknown severity vulnerability in HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5459ada2b3cd69e6bf1b0c034feb810975d0072b <fa95b14198b6c8ea721b4784f466d3c2c2bac83a || >=5459ada2b3cd69e6bf1b0c034feb810975d0072b <9f43499ce6458a572b781f6bb46c464ab59fa825 || >=5459ada2b3cd69e6bf1b0c034feb810975d0072b <bc3d72c44bff17688dc5f3e5132a53b51dae0f04 || >=5459ada2b3cd69e6bf1b0c034feb810975d0072b <c92693f3ed099401d0383ef35ca1fe1e6ba033de | fa95b14198b6c8ea721b4784f466d3c2c2bac83a, 9f43499ce6458a572b781f6bb46c464ab59fa825, bc3d72c44bff17688dc5f3e5132a53b51dae0f04, c92693f3ed099401d0383ef35ca1fe1e6ba033de |
| Linux/Linuxgeneric | 4.9 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature sensor_hub_get_feature() clamps its return value to the caller's buffer size, but the copy loop still copies field->report_size / 8 bytes for each report value. A malicious HID descriptor can advertise a large feature field size while an IIO caller supplies a small stack buffer, such as a single s32, causing an out-of-bounds write. HID core stores parsed report values in __s32 slots and clamps extracted values to 32 bits. Reject feature fields that require more than one slot per value, guard the total byte count calculation, and clamp each per-value copy to the remaining caller buffer.
Quoted source text, attributed separately from HOL analysis.