CVE-2026-80774: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: HID: asus: fix missing hid_is_usb() check to_usb_interface() can only be used on a hid_device whose parent is really USB; uhid can create devices that identify as being on BUS_USB, but don't actually have a USB parent. Fix the use of to_usb_interface() without a hid_is_usb() check. I have verified that it is currently possible to trigger a kernel splat due to this bug in an ASAN build, and that this commit fixes the issue.
Affected products
- Linux Linux: from 6.12.35, before 6.12.108 (fixed in 6.12.108); from 6.15.4, before 6.16 (fixed in 6.16); from 6.16, before 6.18.49 (fixed in 6.18.49); from 6.19, before 7.1.11 (fixed in 7.1.11); from 7.2, before 7.2.1 (fixed in 7.2.1)
Published 2026-09-04. Last modified 2026-09-04.