Junglewise Threat Intelligence

CVE-2026-64365: Linux Kernel HID Letsketch use-after-free in inrange_timer

CVE-2026-64365 · Severity: info · CVSS 4.6 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Letsketch tablet driver could lead to a system crash or unpredictable behavior when the device is unplugged or the driver is removed. This occurs because a background timer used by the driver may continue to run after the driver's memory has been cleared, leading to a 'use-after-free' scenario. This primarily affects the stability and availability of systems using these specific drawing tablets.

Technical details

A use-after-free (UAF) vulnerability exists in the HID Letsketch driver (hid-letsketch.c) within the Linux kernel. The driver initializes a timer (`inrange_timer`) during the probe phase to handle pen-in-range reports, but fails to provide a `.remove` callback to stop the timer when the device is disconnected or the module is unloaded. Consequently, if the timer is armed within 100ms of a device unbind, the callback executes after `letsketch_data` and `input_dev` have been freed by the devm cleanup process. This results in a UAF read and subsequent invalid memory access during `input_report_key()`. The fix involves implementing a `.remove` callback that calls `hid_hw_stop()` and `timer_shutdown_sync()` to ensure the timer is drained and disabled before memory reclamation.

Affected products

  • Linux Linux Kernel 33a5c2793451 to 46c8beeccd8a

Timeline

  • 2026-05-15: other: Patch authored
  • 2026-07-18: patched: Patch committed to stable trees
  • 2026-07-25: disclosed: CVE published

References

Related threats