Description
In the Linux kernel, the following vulnerability has been resolved:

HID: core: quiesce input in hid_hw_stop() to prevent use-after-free

A driver's probe calls hid_device_io_start() to enable input delivery,
then fails at a later initialization step and unwinds via hid_hw_stop().
The unwind frees struct hidraw via hidraw_disconnect() while in-flight
HID reports may still be running on another CPU, dereferencing the
freed object through hidraw_report_event(). syzbot reports the
resulting use-after-free for the corsair-psu HID driver.

Edward Adam Davis posted a per-driver fix for corsair-psu that adds
an explicit hid_device_io_stop() before hid_hw_stop() in the probe
error path ("hwmon: prevent packets from going to driver for probe",
2026-04-28). Auditing the tree shows 15 drivers call
hid_device_io_start(); 7 also call hid_device_io_stop() and 8 do not:

drivers calling hid_device_io_start() without a matching
hid_device_io_stop() before hid_hw_stop():
drivers/hwmon/corsair-psu.c (fix posted by Edward)
drivers/hwmon/corsair-cpro.c
drivers/hwmon/nzxt-kraken3.c
drivers/hwmon/nzxt-smart2.c
drivers/hwmon/gigabyte_waterforce.c
drivers/hid/hid-logitech-dj.c
drivers/hid/hid-nintendo.c
drivers/hid/hid-mcp2221.c

Roughly half of all callers of the API are exposed. Centralize the
quiesce in hid_hw_stop() so callers do not have to remember the
matching stop: if a driver has left hdev->io_started true on entry,
call hid_device_io_stop() before hid_disconnect().

For the 7 drivers that already call hid_device_io_stop() correctly,
hdev->io_started is false on entry, the guard short-circuits, and
behavior is unchanged.

No Fixes: tag because the affected drivers gained their
hid_device_io_start() calls independently over years; the bug is a
class-wide API misuse rather than a regression from one commit.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to possible kernel memory corruption or system crash
Action: Immediate Patch
AI Analysis

Impact

The flaw is in the Linux kernel HID core where input delivery is not properly quiesced when a driver exits during initialization. A driver may call hid_device_io_start to begin receiving input, then unwind and call hid_hw_stop without first stopping input handling. During this process the driver’s hidraw structure is freed while other CPU cores may still be processing HID reports, causing a use‑after‑free. The resulting kernel memory corruption can lead to system crash or other instability. No direct evidence of privilege escalation or arbitrary code execution is documented in the vulnerability description.

Affected Systems

All Linux kernel installations that load any driver that calls hid_device_io_start without a matching hid_device_io_stop may be affected. The current list of affected driver sources includes hwmon/corsair‑psu.c, hwmon/corsair‑cpro.c, hwmon/nzxt‑kraken3.c, hwmon/nzxt‑smart2.c, hwmon/gigabyte_waterforce.c, hid/hid‑logitech‑dj.c, hid/hid‑nintendo.c, and hid/hid‑mcp2221.c. These drivers run on consumer hardware such as Corsair PSU monitors, Logitech gaming devices, Nintendo controllers, and USB‑serial adapters, so a wide range of desktop, laptop, and embedded systems are at risk.

Risk and Exploitability

The CVSS score is 8.8, indicating a high‑severity vulnerability. The reported EPSS is below 1 %, and the flaw is not yet listed in the CISA KEV catalog, which suggests that large‑scale exploitation is not yet observed. However, the flaw requires the faulty driver to be loaded, which typically occurs when the user connects the corresponding hardware. Based on the description, it is inferred that an attacker could trigger the use‑after‑free by sending malformed HID reports, potentially leading to a kernel crash or memory corruption. The attack surface is therefore local to the system’s kernel; remote exploitation would require malicious driver installation or user physical access to the hardware.

Generated by OpenCVE AI on September 20, 2026 at 03:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the corrected logic in hid_hw_stop or apply the patch series referenced in the advisory, such as the commits from the kernel tree that centralize the io_stop call.
  • If an immediate kernel upgrade is not possible, apply the vendor‑specific driver patches that insert hid_device_io_stop before hid_hw_stop for any of the affected drivers (e.g., corsair‑psu, corsair‑cpro, nzxt‑kraken3, nzxt‑smart2, gigabyte_waterforce, hid‑logitech‑dj, hid‑nintendo, or hid‑mcp2221). If no patch is available, black‑list or disable the problematic device so its driver is not loaded.
  • Verify that all drivers in the system that invoke hid_device_io_start also correctly call hid_device_io_stop; work with driver maintainers to fix any missing cleanup before kernel deactivation.
  • Continuously monitor kernel logs for use‑after‑free or KASAN/KMEMLEAK messages that indicate a preceding corruption event, and investigate any unexpected wheel reports to detect potential exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 03:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-587

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: core: quiesce input in hid_hw_stop() to prevent use-after-free A driver's probe calls hid_device_io_start() to enable input delivery, then fails at a later initialization step and unwinds via hid_hw_stop(). The unwind frees struct hidraw via hidraw_disconnect() while in-flight HID reports may still be running on another CPU, dereferencing the freed object through hidraw_report_event(). syzbot reports the resulting use-after-free for the corsair-psu HID driver. Edward Adam Davis posted a per-driver fix for corsair-psu that adds an explicit hid_device_io_stop() before hid_hw_stop() in the probe error path ("hwmon: prevent packets from going to driver for probe", 2026-04-28). Auditing the tree shows 15 drivers call hid_device_io_start(); 7 also call hid_device_io_stop() and 8 do not: drivers calling hid_device_io_start() without a matching hid_device_io_stop() before hid_hw_stop(): drivers/hwmon/corsair-psu.c (fix posted by Edward) drivers/hwmon/corsair-cpro.c drivers/hwmon/nzxt-kraken3.c drivers/hwmon/nzxt-smart2.c drivers/hwmon/gigabyte_waterforce.c drivers/hid/hid-logitech-dj.c drivers/hid/hid-nintendo.c drivers/hid/hid-mcp2221.c Roughly half of all callers of the API are exposed. Centralize the quiesce in hid_hw_stop() so callers do not have to remember the matching stop: if a driver has left hdev->io_started true on entry, call hid_device_io_stop() before hid_disconnect(). For the 7 drivers that already call hid_device_io_stop() correctly, hdev->io_started is false on entry, the guard short-circuits, and behavior is unchanged. No Fixes: tag because the affected drivers gained their hid_device_io_start() calls independently over years; the bug is a class-wide API misuse rather than a regression from one commit.
Title HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:26.212Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93189

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:15.027

Modified: 2026-09-18T18:18:24.110

Link: CVE-2026-93189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-416

    Use After Free

  • CWE-587

    Assignment of a Fixed Address to a Pointer