HID: sensor: custom: Fix use-after-free in enable_sensor
Summary
| CVE | CVE-2026-80767 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-04 16:18:02 UTC |
| Updated | 2026-09-04 16:18:02 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix use-after-free in enable_sensor enable_sensor_store() can call set_power_report_state(), which dereferences sensor_inst->power_state and sensor_inst->report_state. These pointers refer to entries in sensor_inst->fields. Create the field attributes before exposing the enable_sensor sysfs attribute, so enable_sensor cannot be accessed before the state it depends on has been initialized. On remove, delete enable_sensor before freeing the field attributes, so a concurrent sysfs write cannot dereference freed memory through power_state or report_state. |
Risk And Classification
EPSS: 0.001950000 probability, percentile 0.092800000 (date 2026-09-07)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d c2be74b0272b7f8f60739e7aaf0d36c0befe7136 git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855 git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d d37ff4e3635c18af907f25712596f8ccec323751 git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d 2ce90cfc6646a32100feabd7110ae0352aa01167 git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d 244a1cb638370490ed74a8adb5cc3f1212602e32 git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d 8406d4b69d48bc72fb6f8812a65a17a1f903440b git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d c0757f10610542d763bd0bf9bda455b78afeef0b git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d 7bb79a3cf45e0805aef74457e19deb77e18cf196 git | Not specified |
| CNA | Linux | Linux | affected 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d ad8fb82b04422f49530d2aa2753cc81d1c60102c git | Not specified |
| CNA | Linux | Linux | affected 4.1 | Not specified |
| CNA | Linux | Linux | unaffected 4.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.267 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.218 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.185 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.154 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.106 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.47 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.11 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.1 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/c2be74b0272b7f8f60739e7aaf0d36c0befe7136 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2ce90cfc6646a32100feabd7110ae0352aa01167 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8406d4b69d48bc72fb6f8812a65a17a1f903440b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/244a1cb638370490ed74a8adb5cc3f1212602e32 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7bb79a3cf45e0805aef74457e19deb77e18cf196 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ad8fb82b04422f49530d2aa2753cc81d1c60102c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c0757f10610542d763bd0bf9bda455b78afeef0b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d37ff4e3635c18af907f25712596f8ccec323751 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.