Home

Description

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory leak in magicmouse_report_fixup() The magicmouse_report_fixup() function was returning a newly kmemdup()-allocated buffer, but never freeing it. The caller of report_fixup() does not take ownership of the returned pointer, but it *is* permitted to return a sub-portion of the input rdesc, whose lifetime is managed by the caller.

PUBLISHED Reserved 2026-03-09 | Published 2026-04-22 | Updated 2026-04-23 | Assigner Linux

Product status

Default status
unaffected

e6ad399596bd234be4722022146e33e15c7e424d (git) before 579c4c9857acdc8380fa99803f355f878bd766cb
affected

0b91b4e4dae63cd43871fc2012370b86ee588f91 (git) before d84c21aabaab517b9aaf9bc1d785922cb9db2f31
affected

0b91b4e4dae63cd43871fc2012370b86ee588f91 (git) before 7edfe4346b052b708645d0acc0f186425766b785
affected

0b91b4e4dae63cd43871fc2012370b86ee588f91 (git) before 79e5dcc95d9abed6f8203cfd529f4ec71f0e505d
affected

0b91b4e4dae63cd43871fc2012370b86ee588f91 (git) before 136f605e246b4bfe7ac2259471d1ff814aed0084
affected

0b91b4e4dae63cd43871fc2012370b86ee588f91 (git) before fa95b0146358b49f9858139b67314591fd5871b0
affected

0b91b4e4dae63cd43871fc2012370b86ee588f91 (git) before 91e8c6e601bdc1ccdf886479b6513c01c7e51c2c
affected

c394bd1bc8537e61593b6b6799e01495c7cf9008 (git)
affected

Default status
affected

5.17
affected

Any version before 5.17
unaffected

5.15.203 (semver)
unaffected

6.1.168 (semver)
unaffected

6.6.131 (semver)
unaffected

6.12.80 (semver)
unaffected

6.18.21 (semver)
unaffected

6.19.11 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/579c4c9857acdc8380fa99803f355f878bd766cb

git.kernel.org/...c/d84c21aabaab517b9aaf9bc1d785922cb9db2f31

git.kernel.org/...c/7edfe4346b052b708645d0acc0f186425766b785

git.kernel.org/...c/79e5dcc95d9abed6f8203cfd529f4ec71f0e505d

git.kernel.org/...c/136f605e246b4bfe7ac2259471d1ff814aed0084

git.kernel.org/...c/fa95b0146358b49f9858139b67314591fd5871b0

git.kernel.org/...c/91e8c6e601bdc1ccdf886479b6513c01c7e51c2c

cve.org (CVE-2026-31522)

nvd.nist.gov (CVE-2026-31522)

Download JSON