← Back to CVE intelligence
CVE intelligence

CVE-2026-72352

Vulnerability intelligence

Published Aug 15, 2026Sources checked Oct 8, 2026
7.8HIGHCVSS out of 10
What this means

Review the available evidence

CVE-2026-72352 and is rated High severity with a CVSS score of 7.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-72352?

In the Linux kernel, the following vulnerability has been resolved:

HID: bpf: Fix hid_bpf_get_data() range check

hid_bpf_get_data() returns a pointer into the HID-BPF context data when the caller-provided offset and size fit inside ctx->allocated_size.

The current check adds rdwr_buf_size and offset before comparing the result against ctx->allocated_size. Since both values are unsigned, a very large size can wrap the sum below ctx->allocated_size and make the helper return a pointer even though the requested range is not contained in the backing buffer.

Use check_add_overflow() to reject wrapped range ends before comparing the requested range end against ctx->allocated_size.

Source: NVD