CVE-2026-31625

Source
https://cve.org/CVERecord?id=CVE-2026-31625
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31625.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-31625
Downstream
Related
Published
2026-04-24T14:42:42.481Z
Modified
2026-05-18T05:59:52.676268745Z
Summary
HID: alps: fix NULL pointer dereference in alps_raw_event()
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: alps: fix NULL pointer dereference in alpsrawevent()

Commit ecfa6f34492c ("HID: Add HIDCLAIMEDINPUT guards in raw_event callbacks missing them") attempted to fix up the HID drivers that had missed the previous fix that was done in 2ff5baa9b527 ("HID: appleir: Fix potential NULL dereference at raw event handle"), but the alps driver was missed.

Fix this up by properly checking in the hid-alps driver that it had been claimed correctly before attempting to process the raw event.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31625.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
73196ebe134d11a68a2e27814c489d685cfc8b03
Fixed
c8cc765253ad89ccc106a7bdeb5aeac6cf963078
Fixed
8eed7bce7a4c41ab28ee4891103623a12fd41611
Fixed
0091dfa542a362c178a7e9393097138a57d327d1
Fixed
4b618248d2307a219d9431a730cfe1156c8e3386
Fixed
ee2cb3ddfdca949dbc0c3f796ed5a439f0efc9f6
Fixed
1badfc4319224820d5d890f8eab6aa52e4e83339

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31625.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
6.6.136
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.83
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.24
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.14
Type
ECOSYSTEM
Events
Introduced
6.20.0
Fixed
7.0.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31625.json"