Executive brief
A vulnerability in the Linux kernel's Letsketch tablet driver could lead to a system crash or unpredictable behavior when the device is unplugged or the driver is removed. This occurs because a background timer used by the driver may continue to run after the driver's memory has been cleared, leading to a 'use-after-free' scenario. This primarily affects the stability and availability of systems using these specific drawing tablets.
Technical details
A use-after-free (UAF) vulnerability exists in the HID Letsketch driver (hid-letsketch.c) within the Linux kernel. The driver initializes a timer (`inrange_timer`) during the probe phase to handle pen-in-range reports, but fails to provide a `.remove` callback to stop the timer when the device is disconnected or the module is unloaded. Consequently, if the timer is armed within 100ms of a device unbind, the callback executes after `letsketch_data` and `input_dev` have been freed by the devm cleanup process. This results in a UAF read and subsequent invalid memory access during `input_report_key()`. The fix involves implementing a `.remove` callback that calls `hid_hw_stop()` and `timer_shutdown_sync()` to ensure the timer is drained and disabled before memory reclamation.
Affected products
- Linux Linux Kernel 33a5c2793451 to 46c8beeccd8a
Timeline
- 2026-05-15: other: Patch authored
- 2026-07-18: patched: Patch committed to stable trees
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/17f5928d7010bc9e002930326b59e60e40c09ee3
- https://git.kernel.org/stable/c/2bb6e7143cf70ed281822d26c1848b2897ac36e9
- https://git.kernel.org/stable/c/3eca1a8165b5e7996e699e9df76cb4645e184d42
- https://git.kernel.org/stable/c/46c8beeccd8ab2c863827254a85ea877654a3534
- https://git.kernel.org/stable/c/523db788c0f84612707638e266e8957ca7e3a756
- https://git.kernel.org/stable/c/df3d8aa1a9392da3de66398e7a03422463806b21