Executive brief
A vulnerability in the Linux kernel's USB Human Interface Device (HID) driver could cause a system deadlock when using certain multi-function USB devices. This occurs when a device combining input (HID) and storage capabilities undergoes a reset, potentially freezing the system or causing a denial of service. The issue is triggered by improper memory management during the device's error-handling process.
Technical details
A deadlock exists in the Linux kernel's HID subsystem, specifically within the hid_post_reset() and hid_pre_reset() functions in drivers/hid/usbhid/hid-core.c. When a USB device contains both a HID component and a storage (UAS) component, they are reset together, placing the HID reset functions within the block IO error handling path. The vulnerability is caused by using GFP_KERNEL for memory allocations during this phase; if the allocation triggers a reclaim that requires block IO, it deadlocks on the mutex already held for the device reset. The fix involves changing these allocation flags to GFP_NOIO to prevent recursive block IO calls. An attacker would likely need physical access or the ability to trigger USB device resets to exploit this for a local denial of service.
Affected products
- Linux Linux Kernel All versions prior to the fix
Timeline
- 2026-03-24: disclosed: Initial patch authored
- 2026-04-09: patched: Mainline kernel patch committed
- 2026-06-24: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/4e900465296ce9fb12ed47dc77389b8dde95bfe0
- https://git.kernel.org/stable/c/56d318ef8766f0deb08517fd8f3007256ea7997d
- https://git.kernel.org/stable/c/8df2c1b47ee3cd50fd454f75c7a7e2ae8a6adf72
- https://git.kernel.org/stable/c/90550af0aad5e75110073c501e4fb42fca20ff80
- https://git.kernel.org/stable/c/ad4505d2ab3aaac6498f17649608e70e80034bf2
- https://git.kernel.org/stable/c/b3d16611d7cd78e9d5c6baa19b61b7caf9f1ab5e
- https://git.kernel.org/stable/c/c7abd0e6c87441e99c759d40eb6fe589634e3041