Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90329NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

HID: synchronize input before cleaning up a failed probe

hid_device_io_start() allows reports to run concurrently with probe. If
the probe subsequently fails, __hid_device_probe() releases driver
resources and clears hdev->driver without first excluding those report
callbacks.

For example, a report may enter hidraw_report_event() while the failure
path frees the associated hidraw object, leading to a use-after-free when
the report takes the object's list lock.

Stop input before performing failed-probe cleanup. This reacquires
driver_input_lock and waits for any report callback already in progress.
Severity Level
HIGH(8.8)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.34%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 8.8 (HIGH)
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < 3ffb088a2ed34ca982cfc2c81d107ce370aa45f1
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < 2c35cdeb13a0c52429501e66f368fa59cad235f6
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < 98201b46f7e33fe11af6f024fecb40fb56634225
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < 9a3da56aae28e1ad3a3e591f72a537742053ecd2
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < edd490b8ad85c052eaf10dcc9f390ea54f1e1b39
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < 01eeb601a1626e683fb7b77c63f442b06fb87093
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < b85d1000eb8842768970f2fd0a8fd362472d02d5
  • Linux Linux >= c849a6143bec520aff2a6646518b0d041402428b and < 207853d46f7ef2e28042344a1468da8754c3ddbf
  • Linux Linux >= 3.10
Patched Versions
  • Linux Linux 3ffb088a2ed34ca982cfc2c81d107ce370aa45f1
  • Linux Linux 2c35cdeb13a0c52429501e66f368fa59cad235f6
  • Linux Linux 98201b46f7e33fe11af6f024fecb40fb56634225
  • Linux Linux 9a3da56aae28e1ad3a3e591f72a537742053ecd2
  • Linux Linux edd490b8ad85c052eaf10dcc9f390ea54f1e1b39
  • Linux Linux 01eeb601a1626e683fb7b77c63f442b06fb87093
  • Linux Linux b85d1000eb8842768970f2fd0a8fd362472d02d5
  • Linux Linux 207853d46f7ef2e28042344a1468da8754c3ddbf
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.