Junglewise Threat Intelligence

CVE-2026-53037: Linux Kernel deadlock in usbhid during hid_post_reset

CVE-2026-53037 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB Human Interface Device (HID) driver could cause a system deadlock when using certain multi-function USB devices. This occurs when a device combining input (HID) and storage capabilities undergoes a reset, potentially freezing the system or causing a denial of service. The issue is triggered by improper memory management during the device's error-handling process.

Technical details

A deadlock exists in the Linux kernel's HID subsystem, specifically within the hid_post_reset() and hid_pre_reset() functions in drivers/hid/usbhid/hid-core.c. When a USB device contains both a HID component and a storage (UAS) component, they are reset together, placing the HID reset functions within the block IO error handling path. The vulnerability is caused by using GFP_KERNEL for memory allocations during this phase; if the allocation triggers a reclaim that requires block IO, it deadlocks on the mutex already held for the device reset. The fix involves changing these allocation flags to GFP_NOIO to prevent recursive block IO calls. An attacker would likely need physical access or the ability to trigger USB device resets to exploit this for a local denial of service.

Affected products

  • Linux Linux Kernel All versions prior to the fix

Timeline

  • 2026-03-24: disclosed: Initial patch authored
  • 2026-04-09: patched: Mainline kernel patch committed
  • 2026-06-24: advisory: NVD publication date

References

Related threats