VDB
CVE-2026-43111
CVE-2026-43111
PUBLISHED
CVSS 9.300000190734863 CRITICAL
In the Linux kernel, the following vulnerability has been resolved: HID: roccat: fix use-after-free in roccat_report_event roccat_report_event() iterates over the device->readers list without holding the readers_lock. This allows a concurrent roccat_release() to remove and free a reader while it's still being accessed, leading to a use-after-free. Protect the readers list traversal with the readers_lock mutex.
EPSS 0.01% · 2.5th percentile
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.01%
2.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | *, 6.6.136, 6.12.83 |
| linux | linux_kernel | 0, 0, 0 |
Timeline
- May 6, 2026 CVE Published
- May 6, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
References
- https://git.kernel.org/stable/c/e6a445513fbc6a0329d2d5ff375b6725750ec5a6 url
- https://git.kernel.org/stable/c/e16a6d11bd77b81632165f02cf0d5946df74b3b7 url
- https://git.kernel.org/stable/c/36bb2d0b915014bbdc5044982b31b57b78045b93 url
- https://git.kernel.org/stable/c/bca0b595e15450dd66b1153c76c4ef1087ee011b url
- https://git.kernel.org/stable/c/d802d848308b35220f21a8025352f0c0aba15c12 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-43111 advisory