All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80767: HID: sensor: custom: Fix use-after-free in enable_sensor
@ 2026-09-04 15:11 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

HID: sensor: custom: Fix use-after-free in enable_sensor

enable_sensor_store() can call set_power_report_state(), which
dereferences sensor_inst->power_state and sensor_inst->report_state.
These pointers refer to entries in sensor_inst->fields.

Create the field attributes before exposing the enable_sensor sysfs
attribute, so enable_sensor cannot be accessed before the state it
depends on has been initialized.

On remove, delete enable_sensor before freeing the field attributes,
so a concurrent sysfs write cannot dereference freed memory through
power_state or report_state.

The Linux kernel CVE team has assigned CVE-2026-80767 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 5.10.267 with commit c2be74b0272b7f8f60739e7aaf0d36c0befe7136
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 5.15.218 with commit d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 6.1.185 with commit d37ff4e3635c18af907f25712596f8ccec323751
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 6.6.154 with commit 2ce90cfc6646a32100feabd7110ae0352aa01167
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 6.12.106 with commit 244a1cb638370490ed74a8adb5cc3f1212602e32
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 6.18.47 with commit 8406d4b69d48bc72fb6f8812a65a17a1f903440b
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 7.1.11 with commit c0757f10610542d763bd0bf9bda455b78afeef0b
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 7.2.1 with commit 7bb79a3cf45e0805aef74457e19deb77e18cf196
	Issue introduced in 4.1 with commit 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d and fixed in 7.3-rc1 with commit ad8fb82b04422f49530d2aa2753cc81d1c60102c

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80767
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/hid/hid-sensor-custom.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/c2be74b0272b7f8f60739e7aaf0d36c0befe7136
	https://git.kernel.org/stable/c/d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855
	https://git.kernel.org/stable/c/d37ff4e3635c18af907f25712596f8ccec323751
	https://git.kernel.org/stable/c/2ce90cfc6646a32100feabd7110ae0352aa01167
	https://git.kernel.org/stable/c/244a1cb638370490ed74a8adb5cc3f1212602e32
	https://git.kernel.org/stable/c/8406d4b69d48bc72fb6f8812a65a17a1f903440b
	https://git.kernel.org/stable/c/c0757f10610542d763bd0bf9bda455b78afeef0b
	https://git.kernel.org/stable/c/7bb79a3cf45e0805aef74457e19deb77e18cf196
	https://git.kernel.org/stable/c/ad8fb82b04422f49530d2aa2753cc81d1c60102c

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 15:17 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80767: HID: sensor: custom: Fix use-after-free in enable_sensor Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.