GHSA-3wpc-2mx8-q7f6HighCVSS 7.5
In the Linux kernel, the following vulnerability has been resolved: HID: hidpp: fix potential...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
HID: hidpp: fix potential UAF in hidpp_connect_event()
If input_register_device() fails, we call input_free_device(), but keep stale pointer to the old device in hidpp->input, which could potentially lead to UAF. Fix that by resetting it to NULL before returning from hidpp_connect_event().
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-93826
- https://git.kernel.org/stable/c/3303398cc2aa255ba251650a30024e11d48ea6c3
- https://git.kernel.org/stable/c/3b8b2e58b078cd30e121401535541bb8a6d57133
- https://git.kernel.org/stable/c/6df6b1f2c49678211f65647c300bc51dda02893b
- https://git.kernel.org/stable/c/5d7637f4d050d105177217e64b869f56f9825060
- https://git.kernel.org/stable/c/e03fd646adad7f97fa4429ec5f38cee9bde5276e
- https://github.com/advisories/GHSA-3wpc-2mx8-q7f6