Description
In the Linux kernel, the following vulnerability has been resolved:

HID: asus: refactor the two workqueues and init sequence

Multiple issues have been found within the hid-asus driver:
- unchecked size in asus_raw_event()
- unclean teardown of asus_probe on failure
- possible use-after-free in asus_probe
- multiple workqueue used for jobs where one was enough
- sleeping calls in atomic context
- packets of incorrect size being sent to the keyboard controller

Join the two workqueues into one reusing the stopping mechanism
of the brightness workqueue, use the joined workqueue to also
move the asus_wmi_send_event() sleeping call away from atomic
context and add a size check in asus_raw_event().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption and potential privilege escalation
Action: Apply patch
AI Analysis

Impact

In the Linux kernel, the HID ASUS driver contains several critical weaknesses, including unchecked packet size processing in asus_raw_event, an unclean teardown routine that can hide failures in asus_probe, and a possible use–after–free when probe fails. Additionally, the driver performs sleeping calls within an atomic context and sends packets of incorrect size to the keyboard controller. These defects can lead to kernel memory corruption, unexpected crashes, or privilege escalation by an attacker able to inject malformed HID packets.

Affected Systems

The vulnerability affects all Linux distributions running a kernel before the fix that merged the two workqueues and added size checks to the HID ASUS driver. The affected component is the hid_asus module in the core kernel, which is deployed across a wide range of hardware that supports ASUS keyboard firmware. Any system that has not applied the patch commits 47669bec44fe12fe2c7adf2b299e980d7935a2ce or 744b3f930c1173ad57f49b614fc875d8d2715396 remains susceptible.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of exploitation in the wild. However, the lack of a public CVSS score means the exact impact severity is unclear. The likely attack vector requires local privilege access or the ability to direct HID packets to the affected driver, implying that remote exploitation is unlikely but a local attacker or compromised device could trigger the kernel buffer overrun or use–after–free, resulting in a kernel panic or escalation of privileges.

Generated by OpenCVE AI on September 19, 2026 at 04:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the HID ASUS driver patch, such as the commit series available at https://git.kernel.org/stable/commit/?id=47669bec44fe12fe2c7adf2b299e980d7935a2ce or https://git.kernel.org/stable/commit/?id=744b3f930c1173ad57f49b614fc875d8d2715396.
  • If a kernel upgrade is not immediately possible, disable the hid_asus module by adding 'blacklist hid_asus' to /etc/modprobe.d/blacklist.conf and reboot to prevent the driver from loading.
  • Continuously monitor kernel logs for "asus_raw_event" or "asus_probe" related errors and look for signs of memory corruption or use–after–free activity, and apply any subsequent patch releases promptly.

Generated by OpenCVE AI on September 19, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-368
CWE-590

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: asus: refactor the two workqueues and init sequence Multiple issues have been found within the hid-asus driver: - unchecked size in asus_raw_event() - unclean teardown of asus_probe on failure - possible use-after-free in asus_probe - multiple workqueue used for jobs where one was enough - sleeping calls in atomic context - packets of incorrect size being sent to the keyboard controller Join the two workqueues into one reusing the stopping mechanism of the brightness workqueue, use the joined workqueue to also move the asus_wmi_send_event() sleeping call away from atomic context and add a size check in asus_raw_event().
Title HID: asus: refactor the two workqueues and init sequence
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:45.496Z

Reserved: 2026-09-11T19:38:34.803Z

Link: CVE-2026-90331

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:31.610

Modified: 2026-09-17T17:17:31.610

Link: CVE-2026-90331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:45:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-368

    Context Switching Race Condition

  • CWE-590

    Free of Memory not on the Heap