CVE-2026-68359 PUBLISHED

hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop

Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability.

Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 53e68c20aeb1e23419bed811aa3a309ceda200f9 to 185c0880397aee9def0af5a59ea65f22f37ad658 (excl.)
  • affected from 53e68c20aeb1e23419bed811aa3a309ceda200f9 to a2a15de020597efbff84b4281dd472e5860b7e3e (excl.)
  • affected from 53e68c20aeb1e23419bed811aa3a309ceda200f9 to 205cff797a94757ec88ba299c8e2bf2e1e3f4bbf (excl.)
  • affected from 53e68c20aeb1e23419bed811aa3a309ceda200f9 to 18d7c523891004226bccdba39dd681eca22ceb8a (excl.)
  • affected from 53e68c20aeb1e23419bed811aa3a309ceda200f9 to 59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.17 is affected
  • unaffected from 0 to 5.17 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References