{"apiVersion":"1.0","identifier":"CVE-2026-80573","description":"In the Linux kernel, the following vulnerability has been resolved: Input: iforce - validate input packet lengths iforce_process_packet() reads fixed fields from joystick, wheel and status packets without first checking their lengths. In particular, the shared hats-and-buttons helper unconditionally reads data[6]. The status tail is a sequence of 16-bit effect addresses, but an incomplete final address is also consumed. A successful zero-length USB URB additionally reads the packet ID before the common parser is called. Reject the zero-length USB transfer, require the seven-byte joystick and wheel prefixes and the two-byte status prefix, and consume only complete status-tail addresses.","publishedAt":"2026-08-26T15:17:13","lastModifiedAt":"2026-08-27T06:17:42","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80573","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00164,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80573","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80573","en":"https://www.redsauce.net/en/cves/CVE-2026-80573","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80573","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80573","de":"https://www.redsauce.net/de/cves/CVE-2026-80573","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80573","el":"https://www.redsauce.net/el/cves/CVE-2026-80573"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80573"}}