Executive brief
The Linux kernel's Human Interface Device (HID) subsystem contains a use-after-free vulnerability in the device stop logic. When a HID driver fails during initialization and attempts to clean up, in-flight input reports may still be processing on another CPU while the device structures are being freed, leading to a crash or potential code execution. This affects multiple HID drivers including device controllers, gaming peripherals, and hardware monitoring interfaces.
Technical details
The vulnerability is a use-after-free in the HID core subsystem, occurring when hid_hw_stop() is called without a preceding hid_device_io_stop(). When a HID driver's probe fails after calling hid_device_io_start() but before properly quiescing input, the driver unwinds and frees the hidraw structure via hidraw_disconnect(). Meanwhile, in-flight HID reports may still be delivered on another CPU, calling hidraw_report_event() and dereferencing the freed object. The affected drivers (corsair-psu, corsair-cpro, nzxt-kraken3, nzxt-smart2, gigabyte_waterforce, hid-logitech-dj, hid-nintendo, hid-mcp2221) all call hid_device_io_start() during probe without a matching hid_device_io_stop() in the error path. The fix centralizes input quiesce logic in hid_hw_stop() to automatically call hid_device_io_stop() if needed before disconnect, ensuring drivers do not need to remember the matching pair.
Affected products
- Linux Linux kernel Multiple versions with affected HID drivers
- Linux corsair-psu HID driver All versions
- Linux corsair-cpro HID driver All versions
- Linux nzxt-kraken3 HID driver All versions
- Linux nzxt-smart2 HID driver All versions
- Linux gigabyte_waterforce HID driver All versions
- Linux hid-logitech-dj All versions
- Linux hid-nintendo All versions
- Linux hid-mcp2221 All versions
Timeline
- 2026-09-17: disclosed