SB2026090610 - Use-after-free in Linux kernel hid driver
Published: September 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-80766)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to trigger a use-after-free condition.
The vulnerability exists due to a race condition in the uclogic HID driver's in-range timer teardown when processing pen reports during device removal. An attacker with physical access can send pen reports during device removal to trigger a use-after-free condition.
The freed memory is dereferenced in timer-softirq context.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/506fd50a9027340f0e9dcc587d10ccb03312dba6
- https://git.kernel.org/stable/c/849e537160bbb77fe419ecc3944bfe125dcd441b
- https://git.kernel.org/stable/c/9d77ac82e57ead056cf3f71d347083ed9244ad90
- https://git.kernel.org/stable/c/dc5108f18f58870a8dd4203a02a47e571a2be7f0
- https://git.kernel.org/stable/c/e750cdb6de009aace3c77f37fe2173f96175e8e4
- https://git.kernel.org/stable/c/f13d0a00204b05e62336da0ab72ea0d87b56690c
- https://git.kernel.org/stable/c/f1b3ca06380531f49f988f4721d3ed30b0d7a5d2
- https://git.kernel.org/stable/c/f40243358b407aec362fe305fabfcdc94a3abd89