Executive brief
A vulnerability was identified in the Linux kernel's driver for Logitech G15 and similar keyboards. When one of these keyboards is unplugged while certain background tasks (like backlight adjustments) are still running, the system may attempt to access memory that has already been cleared. This could lead to a system crash or unpredictable behavior when the device is physically removed from the computer.
Technical details
A use-after-free vulnerability exists in the lg-g15 HID driver (drivers/hid/hid-lg-g15.c) of the Linux kernel. The driver allocates lg_g15_data using devm and schedules work items from device input handlers (e.g., backlight cycle keys). Because the driver lacked a 'remove' callback to cancel pending work, unplugging the device triggers a race condition where devres frees the data structure while the worker thread is still active or pending. The worker then dereferences the freed memory via container_of. The fix introduces a remove callback that invokes cancel_work_sync() to ensure all background tasks are completed or terminated before the memory is released.
Affected products
- Linux Linux Kernel 97b741aba918 to 33cd1a000daf, 3b9a3919aac6, 4aef9676c26d, 4d0d51bc12d2, 7705b4140d18, 8131f4226688, acce9dee807f, dfc6e61f8311
Timeline
- 2026-06-18: patched: Initial patch authored
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/33cd1a000daf929356aacf2b191d31714ff0615e
- https://git.kernel.org/stable/c/3b9a3919aac6977262f04d5365c0456877522a44
- https://git.kernel.org/stable/c/4aef9676c26dff8723b56834951cfc6b618f0986
- https://git.kernel.org/stable/c/4d0d51bc12d246accbfbb94de05d729c68c9b8fb
- https://git.kernel.org/stable/c/7705b4140d188ce22656f6e541ae7ef834c7e11a
- https://git.kernel.org/stable/c/8131f4226688c4be5f30874d167e44dab838eb09
- https://git.kernel.org/stable/c/acce9dee807f21184fff19ad17c8ed464247e7f7