CVE-2026-68359

Unknown

Last modified

CVE-2026-68359 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop()..

Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 53e68c20aeb1e23419bed811aa3a309ceda200f9, < 185c0880397aee9def0af5a59ea65f22f37ad658; >= 53e68c20aeb1e23419bed811aa3a309ceda200f9, < a2a15de020597efbff84b4281dd472e5860b7e3e; >= 53e68c20aeb1e23419bed811aa3a309ceda200f9, < 205cff797a94757ec88ba299c8e2bf2e1e3f4bbf; >= 53e68c20aeb1e23419bed811aa3a309ceda200f9, < 18d7c523891004226bccdba39dd681eca22ceb8a; >= 53e68c20aeb1e23419bed811aa3a309ceda200f9, < 59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e
LinuxLinux5.17

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68359?
In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().
How severe is CVE-2026-68359?
Severity scoring for CVE-2026-68359 is pending analysis.
How do I fix CVE-2026-68359?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68359?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST