« Volver al listado

CVE-2026-90329

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

HID: synchronize input before cleaning up a failed probe

hid_device_io_start() allows reports to run concurrently with probe. If the probe subsequently fails, __hid_device_probe() releases driver resources and clears hdev->driver without first excluding those report callbacks.

For example, a report may enter hidraw_report_event() while the failure path frees the associated hidraw object, leading to a use-after-free when the report takes the object's list lock.

Stop input before performing failed-probe cleanup. This reacquires driver_input_lock and waits for any report callback already in progress.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vuln. en kernel Linux (AV:A, servicio remoto) permite DoS por use-after-free en HID reports. Explotación requiere acceso de red adyacente; impacto es negación de servicio y potencial escalada local.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90329",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "3ffb088a2ed34ca982cfc2c81d107ce370aa45f1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "2c35cdeb13a0c52429501e66f368fa59cad235f6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "98201b46f7e33fe11af6f024fecb40fb56634225",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "9a3da56aae28e1ad3a3e591f72a537742053ecd2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "edd490b8ad85c052eaf10dcc9f390ea54f1e1b39",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "01eeb601a1626e683fb7b77c63f442b06fb87093",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "b85d1000eb8842768970f2fd0a8fd362472d02d5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c849a6143bec520aff2a6646518b0d041402428b",
              "lessThan": "207853d46f7ef2e28042344a1468da8754c3ddbf",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hid/hid-core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hid/hid-core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:31.307",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/01eeb601a1626e683fb7b77c63f442b06fb87093",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/207853d46f7ef2e28042344a1468da8754c3ddbf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2c35cdeb13a0c52429501e66f368fa59cad235f6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3ffb088a2ed34ca982cfc2c81d107ce370aa45f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/98201b46f7e33fe11af6f024fecb40fb56634225",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a3da56aae28e1ad3a3e591f72a537742053ecd2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b85d1000eb8842768970f2fd0a8fd362472d02d5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/edd490b8ad85c052eaf10dcc9f390ea54f1e1b39",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: synchronize input before cleaning up a failed probe\n\nhid_device_io_start() allows reports to run concurrently with probe. If\nthe probe subsequently fails, __hid_device_probe() releases driver\nresources and clears hdev->driver without first excluding those report\ncallbacks.\n\nFor example, a report may enter hidraw_report_event() while the failure\npath frees the associated hidraw object, leading to a use-after-free when\nthe report takes the object's list lock.\n\nStop input before performing failed-probe cleanup. This reacquires\ndriver_input_lock and waits for any report callback already in progress."
    }
  ],
  "lastModified": "2026-09-18T18:17:54.283",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}