Description
In the Linux kernel, the following vulnerability has been resolved:

HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure

Presently, if the force feedback initialisation fails when probing the
Logitech G920 Driving Force Racing Wheel for Xbox One, an error number
will be returned and propagated before the userspace infrastructure
(sysfs and /dev/input) has been torn down. If userspace ignores the
errors and continues to use its references to these dangling entities, a
UAF will promptly follow.

We have 2 options; continue to return the error, but ensure that all of
the infrastructure is torn down accordingly or continue to treat this
condition as a warning by emitting the message but returning success.
It is thought that the original author's intention was to emit the
warning but keep the device functional, less the force feedback feature,
so let's go with that.
Published: 2026-05-01
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A failure during force‑feedback initialization of the Logitech G920 Driving Force Racing Wheel on Linux exposes the kernel to a use‑after‑free exploit. The kernel returns an error code without properly dismantling the userspace infrastructure, allowing userspace to continue referencing the now‑freed resources. If this is not handled, a use‑after‑free will occur, potentially causing memory corruption or a crash. This is a classic use‑after‑free (CWE‑416) scenario and could enable an attacker to execute arbitrary code with kernel privileges.

Affected Systems

The flaw resides in the Linux kernel’s HID: logitech‑hidpp driver and affects all installations that load this driver for the Logitech G920 (or similar Logitech HIDPP devices). No specific kernel release is specified in the data, so all kernels that include the unpatched version of the driver are potentially impacted.

Risk and Exploitability

Because the vulnerability creates a use‑after‑free (CWE‑416), a successful exploitation could lead to kernel panic or arbitrary code execution, escalating the attacker’s privileges to root. The CVSS score of 7.8 indicates high‑medium severity; the EPSS score of <1% suggests low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The nature of the flaw suggests that exploitation is likely feasible from an unprivileged local attacker who can interact with the problematic device. The likely attack vector is local, and based on the description, it is inferred that it requires physical access to the device or a compromised userspace process that can manipulate the device’s initialization sequence.

Generated by OpenCVE AI on May 7, 2026 at 20:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the patch for the HID: logitech‑hidpp driver to prevent the use‑after‑free condition.
  • If an immediate kernel upgrade is not possible, disable force‑feedback support for the affected device via the appropriate sysfs setting or by removing the device driver module until the patch is applied.
  • Regularly monitor system logs for signs of initialization failures or unhandled errors related to the Logitech G920 to detect potential exploitation attempts early.

Generated by OpenCVE AI on May 7, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CPEs cpe:2.3:o:linux:linux_kernel:5.3.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.4:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.4:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.4:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.4:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 02 May 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 02 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Fri, 01 May 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 01 May 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number will be returned and propagated before the userspace infrastructure (sysfs and /dev/input) has been torn down. If userspace ignores the errors and continues to use its references to these dangling entities, a UAF will promptly follow. We have 2 options; continue to return the error, but ensure that all of the infrastructure is torn down accordingly or continue to treat this condition as a warning by emitting the message but returning success. It is thought that the original author's intention was to emit the warning but keep the device functional, less the force feedback feature, so let's go with that.
Title HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-23T16:06:07.824Z

Reserved: 2026-05-01T14:12:55.979Z

Link: CVE-2026-43049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-01T15:16:51.297

Modified: 2026-05-07T19:05:22.307

Link: CVE-2026-43049

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-01T00:00:00Z

Links: CVE-2026-43049 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T20:45:22Z

Weaknesses