Junglewise Threat Intelligence

CVE-2026-89629: Linux kernel HID corsair-void out-of-bounds read

CVE-2026-89629 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's driver for Corsair Void wireless headsets contained a flaw that could allow a malformed or malicious headset to trigger an out-of-bounds memory read when processing status or firmware event data. While the practical exploitability is limited (requires a compromised device), this could lead to kernel crashes or information disclosure on affected systems.

Technical details

The vulnerability is an out-of-bounds read in the HID (Human Interface Device) corsair-void driver (drivers/hid/hid-corsair-void.c). The corsair_void_raw_event() function processes status and firmware report packets without first validating that the received data buffer is large enough; it directly accesses array indices assuming a minimum size of 5 bytes. A malformed or malicious HID event with a shorter payload could cause the kernel to read beyond the allocated buffer. The fix adds explicit size checks before accessing the data array, returning early if the report size is smaller than expected. The vulnerability requires local or adjacent network access to the HID device (physical USB connection or wireless pairing), and patches are available in Linux kernel versions via commit 08d8814521885e67b1bdf6a3036ee264e3e58377 and later.

Affected products

  • Linux Linux kernel all versions prior to patch commit 08d8814521885e67b1bdf6a3036ee264e3e58377

Timeline

  • 2026-09-11: disclosed: CVE-2026-89629 published

References

Related threats