CVE-2026-89627

Source
https://cve.org/CVERecord?id=CVE-2026-89627
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89627.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-89627
Downstream
Related
Published
2026-09-11T19:45:23Z
Modified
2026-09-25T18:26:56Z
Summary
HID: roccat: free buffered reports when destroying device
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: roccat: free buffered reports when destroying device

roccat_report_event() duplicates each report with kmemdup() and stores the allocation in a circular-buffer slot. The allocation is released only when that slot is reused.

The device destruction paths free struct roccat_device without releasing reports still stored in cbuf[]. This makes those allocations unreachable and leaks up to ROCCAT_CBUF_SIZE report buffers per device.

Add a small destructor that frees every buffered report before freeing the device, and use it in both paths that can destroy a registered device.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89627.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
206f5f2fcb5ff5bb0c60f9e9189937f3ca03e378
Fixed
cebb20b9a29cfc90bf56e54337333084f85a69dd
Fixed
690da9177e64bcfda2f4c0b5b8465178e4a236d8
Fixed
b3cc411daa50b39ba5706492a80a5a0804d9c85f
Fixed
4cb3ff31d237ad1f515455c497ef07d7172d912b
Fixed
943b8dc2c6044c01e36395f51bb809a4b6bdfd22
Fixed
da00eac19feef209c9591e48c860afc2014603be
Fixed
fbb5a60f5c31b5625f0d89a79912fbcb2559289b
Fixed
bbff0ccbff360a5498075525005f6a913239a3d7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89627.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.35
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89627.json"