# CVE-2026-89627

## Summary

- **CVE ID:** CVE-2026-89627
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

HID: roccat: free buffered reports when destroying device

roccat_report_event() duplicates each report with kmemdup() and stores
the allocation in a circular-buffer slot. The allocation is released only
when that slot is reused.

The device destruction paths free struct roccat_device without releasing
reports still stored in cbuf[]. This makes those allocations unreachable
and leaks up to ROCCAT_CBUF_SIZE report buffers per device.

Add a small destructor that frees every buffered report before freeing the
device, and use it in both paths that can destroy a registered device.

## Affected Products

- Linux — Linux (206f5f2fcb5ff5bb0c60f9e9189937f3ca03e378)
- Linux — Linux (2.6.35)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/943b8dc2c6044c01e36395f51bb809a4b6bdfd22)
- [CNA](https://git.kernel.org/stable/c/da00eac19feef209c9591e48c860afc2014603be)
- [CNA](https://git.kernel.org/stable/c/fbb5a60f5c31b5625f0d89a79912fbcb2559289b)
- [CNA](https://git.kernel.org/stable/c/bbff0ccbff360a5498075525005f6a913239a3d7)
- [CNA](https://git.kernel.org/stable/c/cebb20b9a29cfc90bf56e54337333084f85a69dd)
- [CNA](https://git.kernel.org/stable/c/690da9177e64bcfda2f4c0b5b8465178e4a236d8)
- [CNA](https://git.kernel.org/stable/c/b3cc411daa50b39ba5706492a80a5a0804d9c85f)
- [CNA](https://git.kernel.org/stable/c/4cb3ff31d237ad1f515455c497ef07d7172d912b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._