Junglewise Threat Intelligence

CVE-2026-89623: Linux kernel HID mcp2221 use-after-free in device IO cleanup

CVE-2026-89623 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's MCP2221 HID driver has a timing issue during device removal or probe failure where incoming hardware reports can race with the driver's cleanup code, potentially causing the driver to access memory that has already been freed. A fix has been implemented to properly quiesce device input/output before hardware teardown.

Technical details

This is a use-after-free race condition in the MCP2221 HID driver's device unregistration path. The vulnerable component is the mcp2221_hid_unregister() devm cleanup callback, which was calling hid_hw_stop() without first stopping incoming HID reports. An attacker with local access could trigger device removal or probe failure while the device is actively sending reports, causing a race condition where the HID core attempts to process incoming data after device structures have been torn down. The fix adds a guarded call to hid_device_io_stop() at the start of the cleanup callback to quiesce device I/O before hardware teardown. The guard checks the io_started flag to avoid spurious warnings on normal removal paths where the flag has already been cleared by hid_device_remove().

Affected products

  • Linux Linux kernel versions with MCP2221 HID driver support (approximately 5.0 and later, prior to fix commit dca151633c0fde90935311c60e7cfc064aa56134)

Timeline

  • 2026-09-11: disclosed
  • 2026-09-07: patched: Fix committed upstream as dca151633c0fde90935311c60e7cfc064aa56134

References

Related threats