Junglewise Threat Intelligence

CVE-2026-89624: Linux kernel HID universal-pidff use-after-free in device removal

CVE-2026-89624 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's HID force-feedback driver can leave a device in a started state when initialization fails, allowing subsequent access to freed memory. An attacker with local access to a specially crafted HID device could trigger a use-after-free condition when opening the device interface, potentially leading to code execution or system crash.

Technical details

The vulnerability is a use-after-free in the universal_pidff HID driver. When force-feedback initialization fails in universal_pidff_probe(), the device is left in a started state but the driver is unloaded, causing the hidraw character device registration to outlive the underlying device object. When the /dev/hidrawX device is subsequently opened, hid_hw_open() accesses freed memory through the transport's open callback, which attempts to acquire a spinlock within the freed object. This condition is triggered by a HID descriptor with a PID usage page and no input reports, causing hid_hw_start() to succeed but force-feedback init to fail. The fix adds a separate error path that calls hid_hw_stop() before returning on the force-feedback initialization failure.

Affected products

  • Linux Linux kernel affected versions not specified in advisory

Timeline

  • 2026-09-11: disclosed
  • other: Discovered by XBOW, triaged by Baul Lee

Related threats