CVE-2026-80596
Last modified
CVE-2026-80596 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - only expose sysfs attributes on control interface When the driver was converted to use the driver core to instantiate device attributes (via .dev_groups in the usb_driver structure), the attributes started appearing on all interfaces bound to the driver. Since the ims-pcu driver manually claims the secondary data interface during probe, the driver core automatically creates the sysfs attributes for that interface as well. However, the driver only supports these attributes on the primary control interface. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - only expose sysfs attributes on control interface When the driver was converted to use the driver core to instantiate device attributes (via .dev_groups in the usb_driver structure), the attributes started appearing on all interfaces bound to the driver. Since the ims-pcu driver manually claims the secondary data interface during probe, the driver core automatically creates the sysfs attributes for that interface as well. However, the driver only supports these attributes on the primary control interface. Data interfaces lack the necessary descriptors and internal state to handle these requests, and accessing them can lead to unexpected behavior or crashes. Fix this by updating the is_visible() callbacks for both the main and OFN attribute groups to verify that the interface being accessed is indeed the control interface.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 204d18a7a0c67352857dee1bbac517ed63f01d8e, < 7d5e7c8d48f0aaeb9ec90a9a4f450f3c5e422431; >= 204d18a7a0c67352857dee1bbac517ed63f01d8e, < 87e2f89dea078572fb9e13864cec2b1bd8e89b71; >= 204d18a7a0c67352857dee1bbac517ed63f01d8e, < 73e6687be0c1c323a8ec5b733f29440a93e08ff2; >= 204d18a7a0c67352857dee1bbac517ed63f01d8e, < 001428ea4d2c371107cb984108e266adf99f1f1e |
| Linux | Linux | 6.11 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80596?
How severe is CVE-2026-80596?
How do I fix CVE-2026-80596?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80590In the Linux kernel, the following vulnerability has been re…8.6
- CVE-2026-80591In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80592In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80593In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-80594In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80595In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80597In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80598In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80599In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-80600In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-80601In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-80602In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80596?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
