CVE-2024-26717: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid-of: fix NULL-deref on failed power up A while back the I2C HID implementation was split in an ACPI and OF part, but the new OF driver never initialises the client pointer which is dereferenced on power-up failures.

Affected products

  • Linux Linux Kernel: from 5.12, before 5.15.149 (fixed in 5.15.149); from 5.16, before 6.1.79 (fixed in 6.1.79); from 6.2, before 6.6.18 (fixed in 6.6.18); from 6.7, before 6.7.6 (fixed in 6.7.6); version 6.8 only

Published 2024-04-03. Last modified 2026-06-17.