{"id":"CVE-2026-43136","summary":"HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-hidpp: Check maxfield in hidpp_get_report_length()\n\nDo not crash when a report has no fields.\n\nFake USB gadgets can send their own HID report descriptors and can define report\nstructures without valid fields.  This can be used to crash the kernel over USB.","modified":"2026-06-18T03:56:02.574083355Z","published":"2026-05-06T11:27:22.892Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43136.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1547d41f9f19d691c2c9ce4c29f746297baef9e9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1acb28123e57b50d737377f400f57eec889fe5e4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2dc023dbc11b8dfa8afa63242762acd8cddcad03"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7f59999fcd699af06ad2aef446a635ea6aa87db3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae81fac9ce81917817d787e6b74e68482d99bdf2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b74bf7d0d01fa9b53653f58c29aa00772121f6e9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f1ceaaf93ea32d0f2b95c95f784ee155962c52ad"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fb1725c0804dbec9dd01c4cb5c9f1f77a69e36dc"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43136.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43136"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"fe3ee1ec007bf7b10d7c02814d4b8fbe7d9bb435"},{"fixed":"ae81fac9ce81917817d787e6b74e68482d99bdf2"},{"fixed":"2dc023dbc11b8dfa8afa63242762acd8cddcad03"},{"fixed":"7f59999fcd699af06ad2aef446a635ea6aa87db3"},{"fixed":"b74bf7d0d01fa9b53653f58c29aa00772121f6e9"},{"fixed":"f1ceaaf93ea32d0f2b95c95f784ee155962c52ad"},{"fixed":"1acb28123e57b50d737377f400f57eec889fe5e4"},{"fixed":"fb1725c0804dbec9dd01c4cb5c9f1f77a69e36dc"},{"fixed":"1547d41f9f19d691c2c9ce4c29f746297baef9e9"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43136.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.0"},{"fixed":"5.10.252"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.202"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.165"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.128"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.75"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.16"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43136.json"}}],"schema_version":"1.7.5"}