CVE-2026-68091 PUBLISHED

HID: wacom: stop hardware after post-start probe failures

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

HID: wacom: stop hardware after post-start probe failures

wacom_parse_and_register() starts HID hardware before registering inputs and initializing pad LEDs/remotes. Those later steps can fail, but their error paths currently release Wacom resources without stopping the HID hardware.

Route post-hid_hw_start() failures through hid_hw_stop() before releasing driver resources.

This issue was identified during our ongoing static-analysis research while reviewing kernel code.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from f304eb483393f135ab479d02da6f5dc7d9b51cd6 to 5a7ca028facf04921b2c1c2e4d1ee7f282510555 (excl.)
  • affected from 853307924a9003b3142b5253b1caa6625fbad9fc to 3e6473a4f0596182acdda5219b4bebfbee76514f (excl.)
  • affected from e5c6c8ef3e4d3a88407404daafbf2c6be62f2185 to 46d8b8c85ae0589fb85746a64e8908160e52aac3 (excl.)
  • affected from fc41101a94b11cd0d5ad8e213b2b6965f248d653 to 1a1ebdcb56ae58a0ee2c54dd15d75121e30424e3 (excl.)
  • affected from c1d6708bf0d3dd976460d435373cf5abf21ce258 to 75eb2173b63ab41c24d80cd641af18f3c117a267 (excl.)
  • affected from c1d6708bf0d3dd976460d435373cf5abf21ce258 to 416095e9a6037b4b39fcadd0d2bd77a8852211ec (excl.)
  • affected from c1d6708bf0d3dd976460d435373cf5abf21ce258 to e2cc711a9df37f359159b21db56cea9c21f58a9c (excl.)
  • affected from c1d6708bf0d3dd976460d435373cf5abf21ce258 to ec2612b8ad9e642596db011dd8b6568ef1edeaa1 (excl.)
  • Version d943536197c1a05e377452af4ec7942e11d018f4 is affected
  • Version dbaca8fa9ec2c5aa55ec515686ce3b9007554eab is affected
  • Version 79187e8099a9feb550916dbfb962497522022b6d is affected
  • affected from 5.10.210 to 5.10.261 (excl.)
  • affected from 5.15.149 to 5.15.212 (excl.)
  • affected from 6.1.79 to 6.1.178 (excl.)
  • affected from 6.6.18 to 6.6.145 (excl.)
  • affected from 4.19.307 to 4.20 (excl.)
  • affected from 5.4.269 to 5.5 (excl.)
  • affected from 6.7.6 to 6.8 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.8 is affected
  • unaffected from 0 to 6.8 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References