Impact
The flaw is in the Linux kernel HID core where input delivery is not properly quiesced when a driver exits during initialization. A driver may call hid_device_io_start to begin receiving input, then unwind and call hid_hw_stop without first stopping input handling. During this process the driver’s hidraw structure is freed while other CPU cores may still be processing HID reports, causing a use‑after‑free. The resulting kernel memory corruption can lead to system crash or other instability. No direct evidence of privilege escalation or arbitrary code execution is documented in the vulnerability description.
Affected Systems
All Linux kernel installations that load any driver that calls hid_device_io_start without a matching hid_device_io_stop may be affected. The current list of affected driver sources includes hwmon/corsair‑psu.c, hwmon/corsair‑cpro.c, hwmon/nzxt‑kraken3.c, hwmon/nzxt‑smart2.c, hwmon/gigabyte_waterforce.c, hid/hid‑logitech‑dj.c, hid/hid‑nintendo.c, and hid/hid‑mcp2221.c. These drivers run on consumer hardware such as Corsair PSU monitors, Logitech gaming devices, Nintendo controllers, and USB‑serial adapters, so a wide range of desktop, laptop, and embedded systems are at risk.
Risk and Exploitability
The CVSS score is 8.8, indicating a high‑severity vulnerability. The reported EPSS is below 1 %, and the flaw is not yet listed in the CISA KEV catalog, which suggests that large‑scale exploitation is not yet observed. However, the flaw requires the faulty driver to be loaded, which typically occurs when the user connects the corresponding hardware. Based on the description, it is inferred that an attacker could trigger the use‑after‑free by sending malformed HID reports, potentially leading to a kernel crash or memory corruption. The attack surface is therefore local to the system’s kernel; remote exploitation would require malicious driver installation or user physical access to the hardware.
OpenCVE Enrichment
Debian DLA
Debian DSA