CVE-2026-68359

Summary

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop

Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability.

Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().

Affected Software

VendorProductVersion RangeStatus
LinuxLinux53e68c20aeb1e23419bed811aa3a309ceda200f9 < 185c0880397aee9def0af5a59ea65f22f37ad658affected
LinuxLinux53e68c20aeb1e23419bed811aa3a309ceda200f9 < a2a15de020597efbff84b4281dd472e5860b7e3eaffected
LinuxLinux53e68c20aeb1e23419bed811aa3a309ceda200f9 < 205cff797a94757ec88ba299c8e2bf2e1e3f4bbfaffected
LinuxLinux53e68c20aeb1e23419bed811aa3a309ceda200f9 < 18d7c523891004226bccdba39dd681eca22ceb8aaffected
LinuxLinux53e68c20aeb1e23419bed811aa3a309ceda200f9 < 59d104b54b0b42e30fd2a68d24ee5c49dcc54d1eaffected
LinuxLinux5.17affected
LinuxLinux0 < 5.17unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References