Executive brief
A vulnerability in the Linux kernel's Gigabyte AORUS Waterforce AIO cooler driver could allow a system crash when the device is unplugged or the driver probe fails. The bug occurs because the driver does not properly stop device input/output operations before closing the device connection, creating a race condition that could lead to a use-after-free error affecting system stability.
Technical details
The vulnerability is a use-after-free (UAF) race condition in the gigabyte_waterforce hwmon driver. The root cause is that hid_hw_stop() does not actually halt device I/O operations; when the probe function fails after calling hid_device_io_start(), the driver immediately calls hid_hw_stop() without first calling hid_device_io_stop(), leaving device input operations (hid_input_report()) still active on a device that is being stopped. This creates a race window where pending I/O callbacks access freed resources. The fix adds an intermediate error path that calls hid_device_io_stop() before hid_hw_stop() and hid_hw_close(). The vulnerability is network-unreachable and requires the device to be present and the probe to fail, making real-world exploitability limited to denial of service scenarios.
Affected products
- Linux Linux kernel versions before patch commit ff0c5c53d08274e200b48a4d53aa078265e873cb
Timeline
- 2026-08-12: disclosed
- 2026-08-03: patched: patch merged upstream