{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97986","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:18:58.208Z","datePublished":"2026-09-25T10:23:20.801Z","dateUpdated":"2026-10-03T11:01:16.198Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T11:01:16.198Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_input: stop callbacks before unregistering input device\n\nvirtinput_remove() unregisters the input device before resetting the\nvirtio device. virtinput_recv_events() drops vi->lock around input_event(),\nso clearing vi->ready does not stop a callback that passed the entry check.\nIt can still use vi->idev, requeue buffers and kick the queue.\n\nReset first, as virtinput_freeze() already does. With the preceding core\nchange, reset waits for callbacks before input_unregister_device() can\nfree vi->idev. Recheck vi->ready after taking the lock again: keep draining\ncompleted events so an input packet is not truncated, but stop requeueing\nbuffers and kicking the queue.\n\nWith evdev attached, input_unregister_handle() currently waits for an RCU\ngrace period, which also waits out IRQ callbacks. This masks the lifetime\nbug on PCI and MMIO, but does not protect sleepable callbacks on other\ntransports."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/virtio/virtio_input.c"],"versions":[{"version":"271c865161c57cfabca45b93eaa712b19da365bc","lessThan":"3ae729b1f8ab81d1244061872db2fb0ebb110d2a","status":"affected","versionType":"git"},{"version":"271c865161c57cfabca45b93eaa712b19da365bc","lessThan":"81073bca2062c916c818f2744fbab545a5c4982b","status":"affected","versionType":"git"},{"version":"271c865161c57cfabca45b93eaa712b19da365bc","lessThan":"8226aeee9b9a94cd699fbb51cb230feff46cfaf2","status":"affected","versionType":"git"},{"version":"271c865161c57cfabca45b93eaa712b19da365bc","lessThan":"a3ba86a270dd87460759214046dc7cbd409ac711","status":"affected","versionType":"git"},{"version":"271c865161c57cfabca45b93eaa712b19da365bc","lessThan":"5378f7945856a5ed88e6f9850bc7a68f54090135","status":"affected","versionType":"git"},{"version":"271c865161c57cfabca45b93eaa712b19da365bc","lessThan":"d7808b37da0a619cf1fa541c2384e783fecc2480","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/virtio/virtio_input.c"],"versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"7.3-rc3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3ae729b1f8ab81d1244061872db2fb0ebb110d2a"},{"url":"https://git.kernel.org/stable/c/81073bca2062c916c818f2744fbab545a5c4982b"},{"url":"https://git.kernel.org/stable/c/8226aeee9b9a94cd699fbb51cb230feff46cfaf2"},{"url":"https://git.kernel.org/stable/c/a3ba86a270dd87460759214046dc7cbd409ac711"},{"url":"https://git.kernel.org/stable/c/5378f7945856a5ed88e6f9850bc7a68f54090135"},{"url":"https://git.kernel.org/stable/c/d7808b37da0a619cf1fa541c2384e783fecc2480"}],"title":"virtio_input: stop callbacks before unregistering input device","x_generator":{"engine":"bippy-1.2.0"}}}}