← All Advisories

CVE-2026-97538

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97538

Key Details

CVECVE-2026-97538
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (asus_rog_ryujin) Validate HID report lengths

rog_ryujin_raw_event() parses response headers and payload fields without

first checking that they are present in the received report. A short report

can therefore make the driver consume uninitialized bytes from the HID

transport buffer and expose them as sensor values through sysfs.

Validate the response header and the fields used by each response type

before parsing them. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97538
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97538