Junglewise Threat Intelligence

CVE-2026-93189: Linux kernel HID core use-after-free in hid_hw_stop()

CVE-2026-93189 · Severity: high · CVSS 8.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Human Interface Device (HID) subsystem contains a use-after-free vulnerability in the device stop logic. When a HID driver fails during initialization and attempts to clean up, in-flight input reports may still be processing on another CPU while the device structures are being freed, leading to a crash or potential code execution. This affects multiple HID drivers including device controllers, gaming peripherals, and hardware monitoring interfaces.

Technical details

The vulnerability is a use-after-free in the HID core subsystem, occurring when hid_hw_stop() is called without a preceding hid_device_io_stop(). When a HID driver's probe fails after calling hid_device_io_start() but before properly quiescing input, the driver unwinds and frees the hidraw structure via hidraw_disconnect(). Meanwhile, in-flight HID reports may still be delivered on another CPU, calling hidraw_report_event() and dereferencing the freed object. The affected drivers (corsair-psu, corsair-cpro, nzxt-kraken3, nzxt-smart2, gigabyte_waterforce, hid-logitech-dj, hid-nintendo, hid-mcp2221) all call hid_device_io_start() during probe without a matching hid_device_io_stop() in the error path. The fix centralizes input quiesce logic in hid_hw_stop() to automatically call hid_device_io_stop() if needed before disconnect, ensuring drivers do not need to remember the matching pair.

Affected products

  • Linux Linux kernel Multiple versions with affected HID drivers
  • Linux corsair-psu HID driver All versions
  • Linux corsair-cpro HID driver All versions
  • Linux nzxt-kraken3 HID driver All versions
  • Linux nzxt-smart2 HID driver All versions
  • Linux gigabyte_waterforce HID driver All versions
  • Linux hid-logitech-dj All versions
  • Linux hid-nintendo All versions
  • Linux hid-mcp2221 All versions

Timeline

  • 2026-09-17: disclosed

Related threats