Description
In the Linux kernel, the following vulnerability has been resolved:

HID: mcp2221: stop device IO before hid_hw_stop

Quiesce device IO at the start of the devm cleanup callback
mcp2221_hid_unregister() so that incoming HID reports cannot race with
hardware teardown during probe failure or device removal, addressing a
potential use-after-free.

Guard the call to hid_device_io_stop() with io_started. On normal
removal hid_device_remove() has already cleared io_started before the
devres group is released, so an unconditional call would otherwise hit
the !io_started path and emit a spurious "io already stopped" warning
on every removal. The guard preserves the probe-failure balancing,
where io_started is still set after hid_device_io_start(), while
staying silent on the normal removal path.
Published: 2026-09-11
Score: 3.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A race condition exists in the Linux kernel’s mcp2221 HID driver where device I/O is not halted before the hardware teardown. When a probe fails or the device is removed while I/O remains active, the kernel may access freed memory, causing a use‑after‑free that can crash the kernel. The resulting crash represents a denial of service on the affected system.

Affected Systems

All Linux kernel builds that ship the unpatched mcp2221 driver are impacted. Systems that load the mcp2221 driver and have a USB HID device capable of being removed or that can trigger a probe failure are at risk until the kernel is updated with the commit that stops I/O before teardown. This includes most mainstream distributions that load the generic mcp2221 module.

Risk and Exploitability

The CVSS score of 3.9 indicates low severity, and the EPSS score of <1% shows that exploit attempts are unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or device‑level access: an attacker would need to control the USB HID device connected to the target or have the ability to force its removal. This inference is based on the description that the issue occurs during device cleanup.

Generated by OpenCVE AI on September 15, 2026 at 22:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit adding the I/O stop before teardown
  • If an update is not possible, unload or blacklist the mcp2221 driver so that it does not load
  • Physically disconnect any MCP2221 USB HID devices or disable USB HID support to eliminate the attack vector

Generated by OpenCVE AI on September 15, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: stop device IO before hid_hw_stop Quiesce device IO at the start of the devm cleanup callback mcp2221_hid_unregister() so that incoming HID reports cannot race with hardware teardown during probe failure or device removal, addressing a potential use-after-free. Guard the call to hid_device_io_stop() with io_started. On normal removal hid_device_remove() has already cleared io_started before the devres group is released, so an unconditional call would otherwise hit the !io_started path and emit a spurious "io already stopped" warning on every removal. The guard preserves the probe-failure balancing, where io_started is still set after hid_device_io_start(), while staying silent on the normal removal path.
Title HID: mcp2221: stop device IO before hid_hw_stop
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:36.363Z

Reserved: 2026-09-11T19:38:34.737Z

Link: CVE-2026-89623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:47.630

Modified: 2026-09-14T13:19:16.097

Link: CVE-2026-89623

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:20Z

Links: CVE-2026-89623 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:15:17Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference