Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80573— Input: iforce - validate input packet lengths

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: 在 Linux 内核中,以下漏洞已得到修复: 输入:iforce - 验证输入数据包的长度 函数在读取来自游戏手柄、方向盘和状态数据包的固定字段时,未先检查数据包的长度。具体来说,共享的“方向键和按钮”辅助函数无条件读取 。状态数据包的尾部是一系列 16 位的效果地址,但不完整的最后一个地址也会被读取。此外,一次成功的零长度 USB URB 还会在调用通用解析器之前读取数据包 ID。 修复措施: 拒绝零长度的 USB 传输; 要求手柄和方向盘数据包必须包含 7 字节的固定前缀,状态数据

AI Predicted 5.5 Difficulty: Hard EPSS 0.16% · P6

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 0ec411167655ef3ff3e84f6af685e962aff9a75b affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 609be40988898a4d75225ade0ea5c1734757dd33 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< e73d7a7d913d89141321f5f3f16343ecc200d152 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 5232529eaf57f08fe37484e301579a1915b93d14 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 2c083ab16e33fbff3ab8c752fbf8118ed3dd31ce affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< a64a8b6b31cd669f0449138e53cc2592d454ccf1 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 84e5cb517f445dadbd5f8bf4ec513540e51f9c36 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 5751c781d3c97ab6ce0e2a966156ed882152c415 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80573

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Input: iforce - validate input packet lengths
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - validate input packet lengths iforce_process_packet() reads fixed fields from joystick, wheel and status packets without first checking their lengths. In particular, the shared hats-and-buttons helper unconditionally reads data[6]. The status tail is a sequence of 16-bit effect addresses, but an incomplete final address is also consumed. A successful zero-length USB URB additionally reads the packet ID before the common parser is called. Reject the zero-length USB transfer, require the seven-byte joystick and wheel prefixes and the two-byte status prefix, and consume only complete status-tail addresses.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ~ 0ec411167655ef3ff3e84f6af685e962aff9a75b -
Linux Linux 2.6.12 -

II. Public POCs for CVE-2026-80573

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80573

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80573 (7)

Other References for CVE-2026-80573 (1)

Same Patch Batch · Linux · 2026-08-26 · 92 CVEs total

CVE-2026-80519 9.8 CRITICAL ovpn: finish crypto callback cleanup before peer release
CVE-2026-74743 9.8 CRITICAL macvlan: inherit needed_headroom and needed_tailroom from lowerdev
CVE-2026-74737 9.8 CRITICAL net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
CVE-2026-80586 9.8 CRITICAL mptcp: options: reset DSS fields in case of unexpected size
CVE-2026-80587 9.8 CRITICAL mptcp: avoid combining some incoming suboptions
CVE-2026-74744 9.8 CRITICAL ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
CVE-2026-74746 9.8 CRITICAL netfilter: flowtable: publish GC-visible tuple last
CVE-2026-80557 9.8 CRITICAL libceph: fix OOB read in decode_watchers() via missing bounds check
CVE-2026-80558 9.8 CRITICAL libceph: Avoid using invalid osd indices from primary_temp
CVE-2026-80561 9.8 CRITICAL libceph: fix multiple unsafe decodes in decode_locker()
CVE-2026-80528 9.8 CRITICAL ceph: avoid fs reclaim while using current->journal_info
CVE-2026-74752 9.8 CRITICAL sctp: validate cookie AUTH state before use
CVE-2026-80589 9.8 CRITICAL block: stop the timeout timer when releasing a never added disk
CVE-2026-74751 9.4 CRITICAL riscv: lib: Fix ZBB strnlen reading past count boundary
CVE-2026-80585 9.4 CRITICAL mptcp: fastopen: only mark MPTFO subflows with SYN data
CVE-2026-80551 9.3 CRITICAL s390/vfio_ccw: Ensure first IDAW remains constant
CVE-2026-80554 9.3 CRITICAL s390/vfio_ccw: Limit the number of channel program segments
CVE-2026-80553 8.8 HIGH s390/vfio_ccw: Cancel existing workqueues
CVE-2026-80552 8.8 HIGH s390/vfio_ccw: Ensure index for read/write regions are within range
CVE-2026-80576 8.8 HIGH drm/amdgpu: reject oversized IBs with per-ring packet limits

Showing top 20 of 92 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80573

No comments yet


Leave a comment