SB20260918336 - Use-after-free in Linux kernel hid driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-90329)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to a use-after-free in HID failed-probe cleanup when a HID report callback runs concurrently with a failed device probe. A local user can cause a HID report to be processed while a device probe fails to trigger a use-after-free.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01eeb601a1626e683fb7b77c63f442b06fb87093
- https://git.kernel.org/stable/c/207853d46f7ef2e28042344a1468da8754c3ddbf
- https://git.kernel.org/stable/c/2c35cdeb13a0c52429501e66f368fa59cad235f6
- https://git.kernel.org/stable/c/3ffb088a2ed34ca982cfc2c81d107ce370aa45f1
- https://git.kernel.org/stable/c/98201b46f7e33fe11af6f024fecb40fb56634225
- https://git.kernel.org/stable/c/9a3da56aae28e1ad3a3e591f72a537742053ecd2
- https://git.kernel.org/stable/c/b85d1000eb8842768970f2fd0a8fd362472d02d5
- https://git.kernel.org/stable/c/edd490b8ad85c052eaf10dcc9f390ea54f1e1b39