OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93826

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A use-after-free (UAF) vulnerability exists in the Linux kernel's HID subsystem, specifically in the handling of device connections. If the input registration fails, a stale pointer may remain, potentially allowing an attacker to exploit this condition for arbitrary code execution or system instability. Linux users and administrators, particularly those managing HID devices, should prioritize addressing this vulnerability to mitigate associated risks.

CVE
CVE-2026-93826
Severity
HIGH
CVSS
7.5
EPSS
0.23%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: HID: hidpp: fix potential UAF in hidpp_connect_event() If input_register_device() fails, we call input_free_device(), but keep stale pointer to the old device in hidpp->input, which could potentially lead to UAF. Fix that by resetting it to NULL before returning from hidpp_connect_event().