CVE-2026-68360

Source
https://cve.org/CVERecord?id=CVE-2026-68360
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68360.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68360
Downstream
Published
2026-08-10T12:03:37Z
Modified
2026-08-21T03:30:22Z
Summary
hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
Details

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop

Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability.

Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68360.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
40c3a445422579db8ad96c234dbe6c0ab3f6b936
Fixed
3df2b67793babbea7951b5f601d6df891c63b5d8
Fixed
5e07f292ab5591bf4f588aa7abd22ec86c25d076
Fixed
6c5f31fdf28455a7fd573bda452c80b7b6700247
Fixed
0975c42ed2a3bf32125a920e5d19194289126210
Fixed
c7757db58957ac20cdec6ce575dbd44a6375664e
Fixed
56d2deb6448378118dbe68c4fbb3fbae5f65b18c
Fixed
1a634f464d6153dfa4d7e73a3d78236b65a64ee9
Fixed
94c87871b051d7ad758828a805215a2ec194512a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68360.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.9.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68360.json"