{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93826","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.792Z","datePublished":"2026-09-24T16:03:04.711Z","dateUpdated":"2026-10-03T10:57:57.986Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:57.986Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hidpp: fix potential UAF in hidpp_connect_event()\n\nIf input_register_device() fails, we call input_free_device(), but keep\nstale pointer to the old device in hidpp->input, which could potentially\nlead to UAF. Fix that by resetting it to NULL before returning from\nhidpp_connect_event()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The UAF is in hidpp_connect_event(), reached from hidpp_probe() and from hidpp_raw_hidpp_event() on a HID++ short report with rap.sub_id 0x41. DELAYED_INIT devices are Unifying DJ children (PIDs 0x4011/0x4101/0x402d via logi_dj_recv_add_djhid_device) and Bluetooth T651, so the trigger arrives over Unifying 2.4 GHz or Bluetooth HIDP.\nAC:H - The dangling hidpp->input is created only when hidpp_populate_input() stores the new device and input_register_device() then fails, so hidpp_connect_event() calls input_free_device() without clearing the pointer. That register fails on GFP_KERNEL ENOMEM (devres_alloc/input_device_tune_vals), device_add(), or -EINTR on input_mutex, which a HID++ peer cannot induce on demand.\nPR:N - logi_dj_raw_event() delivers Unifying pairing/connect notifications and HID++ reports to the child with no host credential check, and hidpp_probe() binds logitech-hidpp-device during that enumeration; Bluetooth T651 HIDP bind is likewise unauthenticated. No OS account or capability is required.\nUI:N - A REPORT_TYPE_NOTIF_DEVICE_PAIRED/CONNECTED notification (or T651 HIDP connect) runs hidpp_probe() which schedules hidpp_connect_event(); after the failed register, later HID reports handled by wtp_raw_event()/m560_raw_event() dereference hidpp->input. The attacker's peripheral generates both without a victim mount, click, or prompt.\nS:U - The freed object is the delayed struct input_dev allocated by hidpp_allocate_input() and stored in hidpp->input; the UAF stays inside the host kernel HID/input authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - After input_free_device(), wtp_raw_event()/m560_raw_event() still see a non-NULL hidpp->input and call input_mt_get_slot_by_key()/input_event()/input_sync() on the freed input_dev (vals, absinfo, mt slots). UAF of that heap object is an arbitrary-read primitive once the slab is reused.\nI:H - The same dangling hidpp->input is used for input_mt_slot(), input_report_key/rel(), and input_sync(), which write event state and walk handlers on the freed input_dev; heap spray of that object yields arbitrary kernel writes and control-flow hijack.\nA:H - Dereferencing the freed input_dev in wtp_touch_event()/m560_raw_event() after hidpp_connect_event()'s input_free_device() oopses or panics when the object is not reused; hidpp_probe() still succeeds, and DJ's no-op logi_dj_ll_close() keeps delivering reports that retrigger the crash."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-logitech-hidpp.c"],"versions":[{"version":"c39e3d5fc9dd3e16c6f59dd94d827540040de66d","lessThan":"e03fd646adad7f97fa4429ec5f38cee9bde5276e","status":"affected","versionType":"git"},{"version":"c39e3d5fc9dd3e16c6f59dd94d827540040de66d","lessThan":"5d7637f4d050d105177217e64b869f56f9825060","status":"affected","versionType":"git"},{"version":"c39e3d5fc9dd3e16c6f59dd94d827540040de66d","lessThan":"3b8b2e58b078cd30e121401535541bb8a6d57133","status":"affected","versionType":"git"},{"version":"c39e3d5fc9dd3e16c6f59dd94d827540040de66d","lessThan":"3303398cc2aa255ba251650a30024e11d48ea6c3","status":"affected","versionType":"git"},{"version":"c39e3d5fc9dd3e16c6f59dd94d827540040de66d","lessThan":"6df6b1f2c49678211f65647c300bc51dda02893b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-logitech-hidpp.c"],"versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.19","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e03fd646adad7f97fa4429ec5f38cee9bde5276e"},{"url":"https://git.kernel.org/stable/c/5d7637f4d050d105177217e64b869f56f9825060"},{"url":"https://git.kernel.org/stable/c/3b8b2e58b078cd30e121401535541bb8a6d57133"},{"url":"https://git.kernel.org/stable/c/3303398cc2aa255ba251650a30024e11d48ea6c3"},{"url":"https://git.kernel.org/stable/c/6df6b1f2c49678211f65647c300bc51dda02893b"}],"title":"HID: hidpp: fix potential UAF in hidpp_connect_event()","x_generator":{"engine":"bippy-1.2.0"}}}}