{"id":"AZL-100731","summary":"CVE-2026-89624 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: universal-pidff: stop the device when force-feedback init fails\n\nuniversal_pidff_probe() starts the device with hid_hw_start() and then, if\nforce-feedback initialisation fails, returns the error through a label that\nonly does \"return error\".  The device is left started.\n\nThe HID core does not unwind on the driver's behalf.  __hid_device_probe()\nreleases the devres group, closes the report and clears hdev-\u003edriver:\n\n\tif (ret) {\n\t\tdevres_release_group(&hdev-\u003edev, hdev-\u003edevres_group_id);\n\t\thid_close_report(hdev);\n\t\thdev-\u003edriver = NULL;\n\t}\n\nThe hidraw character device that hid_hw_start() registered through\nhid_connect() is allocated with kzalloc() and added with cdev_device_add(),\nso it is not devres-managed and survives that.  With hdev-\u003edriver NULL,\nhid_device_remove() skips hid_hw_stop() as well, because it only unwinds\nwhile a driver is still attached.  The registration therefore outlives the\ndevice on both paths.\n\nOpening the surviving /dev/hidrawX writes into freed memory.  KASAN reports\na use-after-free write from hidraw_open() -\u003e hid_hw_open() -\u003e the\ntransport's open callback, which takes a spinlock inside the freed object.\nA descriptor that carries a PID usage page and no input reports is enough:\nhidraw claims the device so hid_hw_start() succeeds, while hid-\u003einputs\nstays empty so force-feedback init fails.  The other failure returns in\nhid_pidff_init_with_quirks() - no output reports, an allocation failure,\npidff_init_fields(), pidff_check_autocenter(), an unusable effect count,\ninput_ff_create() - all reach the same label.\n\nStop the device on that path.  hid-dr.c and hid-emsff.c, which start the\ndevice with the same HID_CONNECT_DEFAULT & ~HID_CONNECT_FF mask, already do\nthis.  The two earlier gotos must keep returning without hid_hw_stop(),\nsince neither has a started device, so give the path that fails after the\nstart its own label.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e","modified":"2026-09-13T06:06:36Z","published":"2026-09-11T20:19:47Z","upstream":["CVE-2026-89624"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89624"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100731.json"}}],"schema_version":"1.9.0"}