Impact
The Linux kernel HID subsystem allows input reports to execute concurrently with a device probe. If the probe fails, the cleanup routine releases driver resources and clears the driver reference before any running report callbacks finish. Because the HID report callbacks can still run, freeing the resources causes a use‑after‑free that corrupts kernel memory or can be leveraged to execute code with high privileges. The flaw originates from inadequate synchronization around the probe‑cleanup path.
Affected Systems
All Linux kernel builds that compile the standard HID driver and that have not yet incorporated the patch commit are vulnerable. No specific kernel version list is provided, so any kernel prior to the change should be considered at risk.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, but the EPSS score of less than 1 % indicates a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker inserting a malicious HID device—via USB or a spoofed HID‑over‑network interface—to trigger a probe failure and enable the use‑after‑free. Because the flaw only manifests on probe failure, an adversary would need to cause or repeat such a failure, which limits opportunistic exploitation but can be used for targeted attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA