Junglewise Threat Intelligence

CVE-2026-64344: Linux Kernel idmouse use-after-free on disconnect race

CVE-2026-64344 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's idmouse driver, which supports certain USB fingerprint sensors. A race condition occurs when a device is disconnected while being accessed, potentially leading to a system crash or memory corruption. This issue primarily affects systems where these specific USB devices are physically attached and removed.

Technical details

A use-after-free vulnerability exists in drivers/usb/misc/idmouse.c in the Linux kernel. The root cause is a race condition between the release() and disconnect() functions where mutex_unlock() may access a mutex structure after the underlying object's lifetime has ended. Because mutex_unlock() is non-atomic and may access the lock object after releasing it, it cannot safely manage object destruction. The fix introduces kref reference counting to ensure the driver data is only freed after all references, including those held during the unlock sequence, are released. This requires physical access to trigger a device disconnect race.

Affected products

  • Linux Linux 2.6.24 to 6.10.x

Timeline

  • 2026-06-22: patched: Initial patch authored by Johan Hovold
  • 2026-07-25: disclosed: CVE published via kernel.org and NVD

References