CVE-2024-26717 is a local denial-of-service flaw in the Linux kernel's Open Firmware (OF) I2C HID driver at drivers/hid/i2c-hid/i2c-hid-of.c. Introduced in kernel 5.12 when I2C HID support was split into ACPI and OF implementations, the OF driver can leave a client pointer uninitialized; a failed device power-up can then trigger a NULL-pointer dereference and crash or restart the kernel.
The issue is fixed in upstream kernels 5.15.149, 6.1.79, 6.6.18, 6.7.6, and 6.8 and later. Red Hat rated the flaw CVSS 4.4 (low) and released corrected kernel packages for affected RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support systems; its referenced advisory listed RHEL 9 kernel-rt as affected without a corresponding erratum. Organizations should deploy current vendor kernel updates rather than cherry-picking the individual patch.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:7000 and RHSA-2024:7001, fixing affected RHEL 8 kernel and kernel-rt packages for CVE-2024-26717.
Red Hat issued RHSA-2025:10701 to fix the RHEL 9.4 Extended Update Support kernel package for CVE-2024-26717.
Red Hat issued RHSA-2024:9315 to fix the affected RHEL 9 kernel package for CVE-2024-26717.
The issue was fixed in Linux kernel versions 5.15.149, 6.1.79, 6.6.18, 6.7.6, and 6.8. The Linux kernel CVE team recommended upgrading to a current stable release rather than cherry-picking individual patches.
The Linux kernel CVE team assigned CVE-2024-26717 to the NULL-pointer dereference in drivers/hid/i2c-hid/i2c-hid-of.c.
A change that split the I2C HID implementation into ACPI and OF drivers left the OF driver's client pointer uninitialized, creating a NULL-pointer dereference path after failed power-up operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.