CVE-2026-68359
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 53e68c20aeb1e23419bed811aa3a309ceda200f9 < 185c0880397aee9def0af5a59ea65f22f37ad658 | affected |
| Linux | Linux | 53e68c20aeb1e23419bed811aa3a309ceda200f9 < a2a15de020597efbff84b4281dd472e5860b7e3e | affected |
| Linux | Linux | 53e68c20aeb1e23419bed811aa3a309ceda200f9 < 205cff797a94757ec88ba299c8e2bf2e1e3f4bbf | affected |
| Linux | Linux | 53e68c20aeb1e23419bed811aa3a309ceda200f9 < 18d7c523891004226bccdba39dd681eca22ceb8a | affected |
| Linux | Linux | 53e68c20aeb1e23419bed811aa3a309ceda200f9 < 59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e | affected |
| Linux | Linux | 5.17 | affected |
| Linux | Linux | 0 < 5.17 | unaffected |
| Linux | Linux | 6.6.148 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.101 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/185c0880397aee9def0af5a59ea65f22f37ad658
- https://git.kernel.org/stable/c/a2a15de020597efbff84b4281dd472e5860b7e3e
- https://git.kernel.org/stable/c/205cff797a94757ec88ba299c8e2bf2e1e3f4bbf
- https://git.kernel.org/stable/c/18d7c523891004226bccdba39dd681eca22ceb8a
- https://git.kernel.org/stable/c/59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.