HIGH Introduced in 3.10
hid ProbeCleanup UAF
CVE-2026-90329
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.4MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: HID: synchronize input before cleaning up a failed probe hid_device_io_start() allows reports to run concurrently with probe. If the probe subsequently fails, __hid_device_probe() releases driver resources and clears hdev->driver without first excluding those report callbacks. For example, a report may enter hidraw_report_event() while the failure path frees the associated hidraw object, leading to a use-after-free when the report takes the object's list lock. Stop input before performing failed-probe cleanup. This reacquires driver_input_lock and waits for any report callback already in progress.
02KernelScan AI Analysis
Risk summary
A race condition in the HID subsystem allows a use-after-free when a device probe fails while report callbacks are still running. An attacker with physical access to a USB/HID port could trigger this by connecting a malicious device, potentially leading to kernel memory corruption. The vulnerability requires winning a race window during device probing.
Vulnerability analysis
During HID device probing, input reports are allowed to run at the same time as the driver setup. If the setup later fails, the cleanup path releases resources before ensuring that all active report callbacks have finished. A callback still in progress can then operate on memory that was just freed, resulting in a use-after-free in the HID core. The fix prevents this by halting input and waiting for any ongoing callbacks to complete before the cleanup proceeds. An attacker can trigger the flaw by connecting a malicious USB HID device, which requires physical access to a USB port.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.15 | 3.10 | 5.15.221 | 2c35cdeb13a0 |
| 6.1 | 3.10 | 6.1.188 | 98201b46f7e3 |
| 7.2 | 3.10 | 7.2.6 | b85d1000eb88 |
| mainline | 3.10 | 7.3-rc1 | 207853d46f7e |
| 6.18 | 3.10 | 6.18.52 | 01eeb601a162 |
| 5.10 | 3.10 | 5.10.270 | 3ffb088a2ed3 |
| 6.6 | 3.10 | 6.6.157 | 9a3da56aae28 |
| 6.12 | 3.10 | 6.12.110 | edd490b8ad85 |