Executive brief
A flaw in the Linux kernel's HID force-feedback driver can leave a device in a started state when initialization fails, allowing subsequent access to freed memory. An attacker with local access to a specially crafted HID device could trigger a use-after-free condition when opening the device interface, potentially leading to code execution or system crash.
Technical details
The vulnerability is a use-after-free in the universal_pidff HID driver. When force-feedback initialization fails in universal_pidff_probe(), the device is left in a started state but the driver is unloaded, causing the hidraw character device registration to outlive the underlying device object. When the /dev/hidrawX device is subsequently opened, hid_hw_open() accesses freed memory through the transport's open callback, which attempts to acquire a spinlock within the freed object. This condition is triggered by a HID descriptor with a PID usage page and no input reports, causing hid_hw_start() to succeed but force-feedback init to fail. The fix adds a separate error path that calls hid_hw_stop() before returning on the force-feedback initialization failure.
Affected products
- Linux Linux kernel affected versions not specified in advisory
Timeline
- 2026-09-11: disclosed
- other: Discovered by XBOW, triaged by Baul Lee