0.0
NA
CVE-2026-72078
Input: ims-pcu - validate control endpoint type
Description

In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - validate control endpoint type The driver currently assumes that the first endpoint of the control interface is an interrupt IN endpoint without verifying it. A malicious device could provide a different endpoint type, which would then be passed to usb_fill_int_urb(), potentially leading to kernel warnings or undefined behavior. Verify that the control endpoint is an interrupt IN endpoint.

INFO

Published Date :

Aug. 15, 2026, 6:21 a.m.

Last Modified :

Aug. 17, 2026, 6:18 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-72078 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Validate the control endpoint type to prevent kernel issues.
  • Verify the control endpoint is an interrupt IN endpoint.
  • Update the Linux kernel driver.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-72078 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-72078 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-72078 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-72078 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '5de5075a1f26166f172b6687cb66810a9b61e3eb', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '7960d99332e03705ec622d92f31e0c77de8baac6', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '5b96b4da96313dd799a3a40dcfd598d2e2c19217', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'aa1885f87e60c80e59e50ffd5fb096bf02c83e05', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'a630508a09b0c05f14bc0843ed409221a93751aa', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'c8d3d83f2eaaf7659de76e8d44e8fc88ee346042', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'baf56975806534268e24acf9a8abb1c447ce11e9', 'versionType': 'git'}], 'programFiles': ['drivers/input/misc/ims-pcu.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.10'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.10', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/input/misc/ims-pcu.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '5de5075a1f26166f172b6687cb66810a9b61e3eb', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '7960d99332e03705ec622d92f31e0c77de8baac6', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '5b96b4da96313dd799a3a40dcfd598d2e2c19217', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'aa1885f87e60c80e59e50ffd5fb096bf02c83e05', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'a630508a09b0c05f14bc0843ed409221a93751aa', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'c8d3d83f2eaaf7659de76e8d44e8fc88ee346042', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'baf56975806534268e24acf9a8abb1c447ce11e9', 'versionType': 'git'}], 'programFiles': ['drivers/input/misc/ims-pcu.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.10'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.10', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/input/misc/ims-pcu.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '5de5075a1f26166f172b6687cb66810a9b61e3eb', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '7960d99332e03705ec622d92f31e0c77de8baac6', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': '5b96b4da96313dd799a3a40dcfd598d2e2c19217', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'aa1885f87e60c80e59e50ffd5fb096bf02c83e05', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'a630508a09b0c05f14bc0843ed409221a93751aa', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'c8d3d83f2eaaf7659de76e8d44e8fc88ee346042', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e', 'versionType': 'git'}, {'status': 'affected', 'version': '628329d52474323938a03826941e166bc7c8eff4', 'lessThan': 'baf56975806534268e24acf9a8abb1c447ce11e9', 'versionType': 'git'}], 'programFiles': ['drivers/input/misc/ims-pcu.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.10'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.10', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/input/misc/ims-pcu.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - validate control endpoint type The driver currently assumes that the first endpoint of the control interface is an interrupt IN endpoint without verifying it. A malicious device could provide a different endpoint type, which would then be passed to usb_fill_int_urb(), potentially leading to kernel warnings or undefined behavior. Verify that the control endpoint is an interrupt IN endpoint.
    Added Reference https://git.kernel.org/stable/c/5b96b4da96313dd799a3a40dcfd598d2e2c19217
    Added Reference https://git.kernel.org/stable/c/5de5075a1f26166f172b6687cb66810a9b61e3eb
    Added Reference https://git.kernel.org/stable/c/7960d99332e03705ec622d92f31e0c77de8baac6
    Added Reference https://git.kernel.org/stable/c/a630508a09b0c05f14bc0843ed409221a93751aa
    Added Reference https://git.kernel.org/stable/c/aa1885f87e60c80e59e50ffd5fb096bf02c83e05
    Added Reference https://git.kernel.org/stable/c/baf56975806534268e24acf9a8abb1c447ce11e9
    Added Reference https://git.kernel.org/stable/c/c8d3d83f2eaaf7659de76e8d44e8fc88ee346042
    Added Reference https://git.kernel.org/stable/c/cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.