CVE-2026-80572

HIGHCVSS 7.8/10

Last modified

CVE-2026-80572 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: Input: byd - synchronize timer deletion before freeing private data byd_disconnect() uses timer_delete() before freeing the driver's private data. This does not wait for a running byd_clear_touch() callback, which dereferences the private data and its psmouse pointer.

Description

In the Linux kernel, the following vulnerability has been resolved: Input: byd - synchronize timer deletion before freeing private data byd_disconnect() uses timer_delete() before freeing the driver's private data. This does not wait for a running byd_clear_touch() callback, which dereferences the private data and its psmouse pointer. A callback racing with disconnect can therefore access the private data after it has been freed. The timer can also still be re-armed by byd_process_byte() while the disconnect is in progress. Use timer_shutdown_sync() before freeing the private data: it waits for a running callback and turns any later re-arm attempt into a no-op.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 2d5f5611dd0de52e9a52b56391a7049a52184e72, < 84b205297fa15f97510342221d8c9a0119711478; >= 2d5f5611dd0de52e9a52b56391a7049a52184e72, < 28d984a66b9e14be74986167b6ad40b5e0daf19a; >= 2d5f5611dd0de52e9a52b56391a7049a52184e72, < ee944a706a18322b4a2599eebe8040a2994e928f; >= 2d5f5611dd0de52e9a52b56391a7049a52184e72, < 8dbfd8e32a13e116790780ed0be82b5a05eb9916; >= 2d5f5611dd0de52e9a52b56391a7049a52184e72, < 2e509ef60ee41a2da0deb062c262bb530143fb37; >= 2d5f5611dd0de52e9a52b56391a7049a52184e72, < c83e79c0842ed29860648bcce5022ef0ba5001c6
LinuxLinux4.6

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-80572?
In the Linux kernel, the following vulnerability has been resolved: Input: byd - synchronize timer deletion before freeing private data byd_disconnect() uses timer_delete() before freeing the driver's private data. This does not wait for a running byd_clear_touch() callback, which dereferences the private data and its psmouse pointer. A callback racing with disconnect can therefore access the private data after it has been freed. The timer can also still be re-armed by byd_process_byte() while the disconnect is in progress. Use timer_shutdown_sync() before freeing the private data: it waits for a running callback and turns any later re-arm attempt into a no-op.
How severe is CVE-2026-80572?
CVE-2026-80572 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-80572?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-80572?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST