cbcvebase.
CVE-2026-23349
published 2026-03-25

CVE-2026-23349: In the Linux kernel, the following vulnerability has been resolved: HID: pidff: Fix condition effect bit clearing As reported by MPDarkGuy on discord, NULL…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved: HID: pidff: Fix condition effect bit clearing As reported by MPDarkGuy on discord, NULL pointer dereferences were happening because not all the conditional effects bits were cleared. Properly clear all conditional effect bits from ffbit

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 7f3d7bc0df4bdc23d31cf0f90b6e20c45129465e < d1edc027a4b0bb4c7a2670b530590b4df6177011d1edc027a4b0bb4c7a2670b530590b4df6177011
linuxlinux>= 7f3d7bc0df4bdc23d31cf0f90b6e20c45129465e < ef0e669dbceaf3d7bb4ae0b235fa61feabd92b0bef0e669dbceaf3d7bb4ae0b235fa61feabd92b0b
linuxlinux>= 7f3d7bc0df4bdc23d31cf0f90b6e20c45129465e < 97d5c8f5c09a604c4873c8348f58de3cea69a7df97d5c8f5c09a604c4873c8348f58de3cea69a7df
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 6.18.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.18.1 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.