Description
In the Linux kernel, the following vulnerability has been resolved:

HID: synchronize input before cleaning up a failed probe

hid_device_io_start() allows reports to run concurrently with probe. If
the probe subsequently fails, __hid_device_probe() releases driver
resources and clears hdev->driver without first excluding those report
callbacks.

For example, a report may enter hidraw_report_event() while the failure
path frees the associated hidraw object, leading to a use-after-free when
the report takes the object's list lock.

Stop input before performing failed-probe cleanup. This reacquires
driver_input_lock and waits for any report callback already in progress.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel memory corruption and potential arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel HID subsystem allows input reports to execute concurrently with a device probe. If the probe fails, the cleanup routine releases driver resources and clears the driver reference before any running report callbacks finish. Because the HID report callbacks can still run, freeing the resources causes a use‑after‑free that corrupts kernel memory or can be leveraged to execute code with high privileges. The flaw originates from inadequate synchronization around the probe‑cleanup path.

Affected Systems

All Linux kernel builds that compile the standard HID driver and that have not yet incorporated the patch commit are vulnerable. No specific kernel version list is provided, so any kernel prior to the change should be considered at risk.

Risk and Exploitability

The CVSS score of 8.8 reflects high severity, but the EPSS score of less than 1 % indicates a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker inserting a malicious HID device—via USB or a spoofed HID‑over‑network interface—to trigger a probe failure and enable the use‑after‑free. Because the flaw only manifests on probe failure, an adversary would need to cause or repeat such a failure, which limits opportunistic exploitation but can be used for targeted attacks.

Generated by OpenCVE AI on September 19, 2026 at 14:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel version that contains the HID synchronization fix or apply the upstream patch commit directly.
  • Reboot the system so the updated kernel and driver code takes effect.
  • If an immediate kernel upgrade is impossible, disable hotplug HID drivers with kernel configuration or unload the relevant modules, and disconnect nonessential HID devices until the patch can be applied.

Generated by OpenCVE AI on September 19, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: synchronize input before cleaning up a failed probe hid_device_io_start() allows reports to run concurrently with probe. If the probe subsequently fails, __hid_device_probe() releases driver resources and clears hdev->driver without first excluding those report callbacks. For example, a report may enter hidraw_report_event() while the failure path frees the associated hidraw object, leading to a use-after-free when the report takes the object's list lock. Stop input before performing failed-probe cleanup. This reacquires driver_input_lock and waits for any report callback already in progress.
Title HID: synchronize input before cleaning up a failed probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:40.648Z

Reserved: 2026-09-11T19:38:34.803Z

Link: CVE-2026-90329

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:31.307

Modified: 2026-09-18T18:17:54.283

Link: CVE-2026-90329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses