CVE-2026-31522: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory leak in magicmouse_report_fixup() The magicmouse_report_fixup() function was returning a newly kmemdup()-allocated buffer, but never freeing it. The caller of report_fixup() does not take ownership of the returned pointer, but it *is* permitted to return a sub-portion of the input rdesc, whose lifetime is managed by the caller.
Affected products
- Linux Linux Kernel: from 5.15.17, before 5.15.203 (fixed in 5.15.203); from 5.16.3, before 5.17 (fixed in 5.17); from 5.17, before 6.1.168 (fixed in 6.1.168); from 6.2, before 6.6.131 (fixed in 6.6.131); from 6.7, before 6.12.80 (fixed in 6.12.80); from 6.13, before 6.18.21 (fixed in 6.18.21); …
Published 2026-04-22. Last modified 2026-06-17.