HID: lg-g15: cancel pending work on remove to fix a use-after-free

Summary

CVECVE-2026-64362
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:18 UTC
Updated2026-07-25 10:17:18 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: HID: lg-g15: cancel pending work on remove to fix a use-after-free lg_g15_data is allocated with devm and holds a work item. The report handlers schedule that work straight from device input. lg_g15_event() and lg_g15_v2_event() do it on the backlight cycle key, and lg_g510_leds_event() does it too. The worker dereferences the lg_g15_data back through container_of. The driver had no remove callback and never cancelled the work. So if a report scheduled the work and the keyboard was then unplugged, devres freed lg_g15_data while the work was still pending or running, and the worker touched freed memory. This is a use-after-free. It is reachable as a race on device unplug. Add a remove callback that cancels the work before devres frees the state. g15->work is only initialized for the models that schedule it (G15, G15 v2, G510). The G13 and Z-10 leave it zeroed, so guard the cancel on g15->work.func to avoid cancelling a work that was never set up. The g15 NULL test mirrors the one already in lg_g15_raw_event().

Risk And Classification

EPSS: 0.001770000 probability, percentile 0.075090000 (date 2026-07-28)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 3b9a3919aac6977262f04d5365c0456877522a44 git Not specified
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 4aef9676c26dff8723b56834951cfc6b618f0986 git Not specified
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 acce9dee807f21184fff19ad17c8ed464247e7f7 git Not specified
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 33cd1a000daf929356aacf2b191d31714ff0615e git Not specified
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 dfc6e61f83113cc18346b6988f07271c0063357d git Not specified
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 4d0d51bc12d246accbfbb94de05d729c68c9b8fb git Not specified
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 8131f4226688c4be5f30874d167e44dab838eb09 git Not specified
CNA Linux Linux affected 97b741aba918c4143f4208d2421d08ff215c1b49 7705b4140d188ce22656f6e541ae7ef834c7e11a git Not specified
CNA Linux Linux affected 5.5 Not specified
CNA Linux Linux unaffected 5.5 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/4aef9676c26dff8723b56834951cfc6b618f0986 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3b9a3919aac6977262f04d5365c0456877522a44 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/acce9dee807f21184fff19ad17c8ed464247e7f7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dfc6e61f83113cc18346b6988f07271c0063357d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4d0d51bc12d246accbfbb94de05d729c68c9b8fb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7705b4140d188ce22656f6e541ae7ef834c7e11a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8131f4226688c4be5f30874d167e44dab838eb09 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/33cd1a000daf929356aacf2b191d31714ff0615e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report