CVE-2026-23196
published 2026-02-14CVE-2026-23196: In the Linux kernel, the following vulnerability has been resolved: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer Add DMA buffer…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.10%
1.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
Add DMA buffer readiness check before reading DMA buffer to avoid
unexpected NULL pointer accessing.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.10-1 (forky) | linux 6.18.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 4138f21115aec3ebae7805ec3407c72d93558023 < 1e84a807c98a71f767fd1f609637bc5944f916cb | 1e84a807c98a71f767fd1f609637bc5944f916cb |
| linux | linux | >= 4138f21115aec3ebae7805ec3407c72d93558023 < a9a917998d172ec117f9e9de1919174153c0ace4 | a9a917998d172ec117f9e9de1919174153c0ace4 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.18.10-1 | 6.18.10-1 |
| linux | linux_kernel | >= 6.14 < 6.18.10 | 6.18.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
vendor_redhat·2026-02-14·CVSS 5.5
CVE-2026-23196 [MEDIUM] CWE-476 kernel: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
kernel: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
Add DMA buffer readiness check before reading DMA buffer to avoid
unexpected NULL pointer accessing.
A NULL pointer dereference was found in the Intel THC (Touch Host Controller) HID driver. The driver reads from a DMA buffer without first checking if the buffer is ready, which can result in accessing a NULL pointer and crashing the kernel.
Statement: This affects systems with Intel THC touchscreen/touchpad controllers. The NULL pointer access occurs when the DMA buffer is accessed before initialization completes, requiring specific timing during device initialization or o
Debian
CVE-2026-23196: linux - In the Linux kernel, the following vulnerability has been resolved: HID: Intel-...
vendor_debian·2026·CVSS 5.5
CVE-2026-23196 [MEDIUM] CVE-2026-23196: linux - In the Linux kernel, the following vulnerability has been resolved: HID: Intel-...
In the Linux kernel, the following vulnerability has been resolved: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer Add DMA buffer readiness check before reading DMA buffer to avoid unexpected NULL pointer accessing.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.18.10-1)
sid: resolved (fixed in 6.18.10-1)
trixie: resolved
VulDB
Linux Kernel up to 6.18.9 HID null pointer dereference (EUVD-2026-6107 / Nessus ID 299105)
vuldb·2026-05-05·CVSS 5.5
CVE-2026-23196 [MEDIUM] Linux Kernel up to 6.18.9 HID null pointer dereference (EUVD-2026-6107 / Nessus ID 299105)
A vulnerability classified as critical was found in Linux Kernel up to 6.18.9. This impacts an unknown function of the component HID. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-23196. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
GHSA
GHSA-hqf5-283c-2wrw: In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
Add DMA b
ghsa_unreviewed·2026-02-14
CVE-2026-23196 [MEDIUM] CWE-476 GHSA-hqf5-283c-2wrw: In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
Add DMA b
In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
Add DMA buffer readiness check before reading DMA buffer to avoid
unexpected NULL pointer accessing.
OSV
CVE-2026-23196: In the Linux kernel, the following vulnerability has been resolved: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer Add DMA buf
osv·2026-02-14·CVSS 5.5
CVE-2026-23196 [MEDIUM] CVE-2026-23196: In the Linux kernel, the following vulnerability has been resolved: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer Add DMA buf
In the Linux kernel, the following vulnerability has been resolved: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer Add DMA buffer readiness check before reading DMA buffer to avoid unexpected NULL pointer accessing.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23196 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-23196 [MEDIUM] CVE-2026-23196 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23196 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
Add DMA buffer readiness check before reading DMA buffer to avoid
unexpected NULL pointer accessing.
Source : NVD
## 5.5
Score
Published February 14, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-debug-core
kernel-64k-debug-core
Sources
NVD
Debian 11, 12, 13 No Fix Added at: Feb 15, 2026
Debian 14 Severity M
Bugzilla
CVE-2026-23196 kernel: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
bugzilla·2026-02-14·CVSS 5.5
CVE-2026-23196 [MEDIUM] CVE-2026-23196 kernel: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
CVE-2026-23196 kernel: HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: Add safety check for reading DMA buffer
Add DMA buffer readiness check before reading DMA buffer to avoid
unexpected NULL pointer accessing.
2026-02-14
Published