CVE-2026-97986
In the Linux kernel, the following vulnerability has been resolved:
virtio_input: stop callbacks before unregistering input device
virtinput_remove() unregisters the input device before resetting the virtio device. virtinput_recv_events() drops vi->lock around input_event(), so clearing vi->ready does not stop a callback that passed the entry check. It can still use vi->idev, requeue buffers and kick the queue.
Reset first, as virtinput_freeze() already does. With the preceding core change, reset waits for callbacks before input_unregister_device() can free vi->idev. Recheck vi->ready after taking the lock again: keep draining completed events so an input packet is not truncated, but stop requeueing buffers and kicking the queue.
Leer descripción completaMostrar menos
With evdev attached, input_unregister_handle() currently waits for an RCU grace period, which also waits out IRQ callbacks. This masks the lifetime bug on PCI and MMIO, but does not protect sleepable callbacks on other transports.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/3ae729b1f8ab81d1244061872db2fb0ebb110d2a
- https://git.kernel.org/stable/c/5378f7945856a5ed88e6f9850bc7a68f54090135
- https://git.kernel.org/stable/c/81073bca2062c916c818f2744fbab545a5c4982b
- https://git.kernel.org/stable/c/8226aeee9b9a94cd699fbb51cb230feff46cfaf2
- https://git.kernel.org/stable/c/a3ba86a270dd87460759214046dc7cbd409ac711
- https://git.kernel.org/stable/c/d7808b37da0a619cf1fa541c2384e783fecc2480
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97986",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "271c865161c57cfabca45b93eaa712b19da365bc",
"lessThan": "3ae729b1f8ab81d1244061872db2fb0ebb110d2a",
"versionType": "git"
},
{
"status": "affected",
"version": "271c865161c57cfabca45b93eaa712b19da365bc",
"lessThan": "81073bca2062c916c818f2744fbab545a5c4982b",
"versionType": "git"
},
{
"status": "affected",
"version": "271c865161c57cfabca45b93eaa712b19da365bc",
"lessThan": "8226aeee9b9a94cd699fbb51cb230feff46cfaf2",
"versionType": "git"
},
{
"status": "affected",
"version": "271c865161c57cfabca45b93eaa712b19da365bc",
"lessThan": "a3ba86a270dd87460759214046dc7cbd409ac711",
"versionType": "git"
},
{
"status": "affected",
"version": "271c865161c57cfabca45b93eaa712b19da365bc",
"lessThan": "5378f7945856a5ed88e6f9850bc7a68f54090135",
"versionType": "git"
},
{
"status": "affected",
"version": "271c865161c57cfabca45b93eaa712b19da365bc",
"lessThan": "d7808b37da0a619cf1fa541c2384e783fecc2480",
"versionType": "git"
}
],
"programFiles": [
"drivers/virtio/virtio_input.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/virtio/virtio_input.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:26.683",
"references": [
{
"url": "https://git.kernel.org/stable/c/3ae729b1f8ab81d1244061872db2fb0ebb110d2a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5378f7945856a5ed88e6f9850bc7a68f54090135",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/81073bca2062c916c818f2744fbab545a5c4982b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8226aeee9b9a94cd699fbb51cb230feff46cfaf2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a3ba86a270dd87460759214046dc7cbd409ac711",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d7808b37da0a619cf1fa541c2384e783fecc2480",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_input: stop callbacks before unregistering input device\n\nvirtinput_remove() unregisters the input device before resetting the\nvirtio device. virtinput_recv_events() drops vi->lock around input_event(),\nso clearing vi->ready does not stop a callback that passed the entry check.\nIt can still use vi->idev, requeue buffers and kick the queue.\n\nReset first, as virtinput_freeze() already does. With the preceding core\nchange, reset waits for callbacks before input_unregister_device() can\nfree vi->idev. Recheck vi->ready after taking the lock again: keep draining\ncompleted events so an input packet is not truncated, but stop requeueing\nbuffers and kicking the queue.\n\nWith evdev attached, input_unregister_handle() currently waits for an RCU\ngrace period, which also waits out IRQ callbacks. This masks the lifetime\nbug on PCI and MMIO, but does not protect sleepable callbacks on other\ntransports."
}
],
"lastModified": "2026-10-03T11:18:22.500",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}