Executive brief
A security vulnerability was identified in the Linux kernel's Apple Infrared (AppleIR) receiver driver. This flaw could allow a local attacker or a malicious device to cause a system crash or potentially execute unauthorized code when the infrared receiver is disconnected. The issue occurs because the system tries to access memory associated with the device after it has already been removed from the computer.
Technical details
A use-after-free (UAF) vulnerability exists in the appleir driver (drivers/hid/hid-appleir.c) due to a race condition during device removal. The appleir_remove() function previously called hid_hw_stop() before ensuring all pending timers were fully shut down. This allowed key_up_tick() or appleir_raw_event() to dereference appleir->input_dev after it had been freed by the input subsystem. The fix introduces a 'removing' flag protected by a spinlock and utilizes timer_shutdown_sync() to ensure no further timer callbacks or re-arming can occur during teardown. This vulnerability requires physical access to disconnect the device or a local attacker capable of triggering driver removal.
Affected products
- Linux Linux Kernel Introduced in 9a4a5574ce42; fixed in 6.10, 6.6.42, 6.1.101, 5.15.164, 5.10.223, 5.4.281, 4.19.319
Timeline
- 2026-07-17: patched: Initial fix authored
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/05e3decc55d1deca9410e0eb36466651fcbe57a5
- https://git.kernel.org/stable/c/3755f6e25776b8b12ddf062f9b573f05090e4034
- https://git.kernel.org/stable/c/37a52c61d4f78153c38ae1f7491dfcc8ac828dcf
- https://git.kernel.org/stable/c/3d30a0bb0e79621ae921b487835c56198adfafa3
- https://git.kernel.org/stable/c/6b0838e86da88b1d3bff86f19761ff25af73eaca
- https://git.kernel.org/stable/c/75fe87e19d8aff81eb2c64d15d244ab8da4de945
- https://git.kernel.org/stable/c/89ef67359672bf4cd6921524e39f61648fe38c0f