Race condition in Linux kernel - CVE-2026-80559
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a system crash.
The vulnerability exists due to a race condition in the sur40 input device initialization and polling path when opening the input device before the V4L2 video device and vb2_queue are fully initialized. A local user can open the device to trigger the polling worker thread and cause a system crash.
The issue is triggered during device initialization ordering in sur40_probe().
Affected software
How to mitigate CVE-2026-80559
External References
- https://git.kernel.org/stable/c/3e8ed76a4f3572e637653f0654cccdf617903231
- https://git.kernel.org/stable/c/5c1c5227c93f18cd329dd754b4df5e0e2daece1e
- https://git.kernel.org/stable/c/764b507be7b51787e1f577ca3bf0bab7efe81ff8
- https://git.kernel.org/stable/c/83aa12f9f2468a4fbef027c09224dc1011850fb0
- https://git.kernel.org/stable/c/9da976eb649c9e2f588a4499410e4d8af687925f
- https://git.kernel.org/stable/c/beb9b0bd6e6e23f5e9e42b7ef890a50f57f1f3aa
- https://git.kernel.org/stable/c/cd4ecce2fd87760c0ad9a9d28c9fc62ea1dbfd3d
- https://git.kernel.org/stable/c/dab741c9da72102a37cc1020a929051b7c45f9fb