CVE-2026-80596
CVE CVE-2026-80596EUVD EUVD-2026-67472Veröffentlicht 2026-08-28T06:48:22.000ZZuletzt geändert 2026-08-29T06:21:08.000ZCVSS 8.4
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - only expose sysfs attributes on control interface When the driver was converted to use the driver core to instantiate device attributes (via .dev_groups in the usb_driver structure), the attributes started appearing on all interfaces bound to the driver. Since the ims-pcu driver manually claims the secondary data interface during probe, the driver core automatically creates the sysfs attributes for that interface as well. However, the driver only supports these attributes on the primary control interface. Data interfaces lack the necessary descriptors and internal state to handle these requests, and accessing them can lead to unexpected behavior or crashes. Fix this by updating the is_visible() callbacks for both the main and OFN attribute groups to verify that the interface being accessed is indeed the control interface.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 6.11; 204d18a7a0c67352857dee1bbac517ed63f01d8e <73e6687be0c1c323a8ec5b733f29440a93e08ff2; 204d18a7a0c67352857dee1bbac517ed63f01d8e <87e2f89dea078572fb9e13864cec2b1bd8e89b71; patch: 6.18.40; patch: 7.1.5; patch: 0; 204d18a7a0c67352857dee1bbac517ed63f01d8e <7d5e7c8d48f0aaeb9ec90a9a4f450f3c5e422431; patch: 7.2; 204d18a7a0c67352857dee1bbac517ed63f01d8e <001428ea4d2c371107cb984108e266adf99f1f1e; patch: 6.12.97
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.