{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop  hid_hw_stop() does not stop the device IO.  This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within corsairpsu_probe(). If the probe operation fails after \"io start\" has been initiated, this race condition will result in a uaf vulnerability [1].  CPU0\t\t\t\tCPU1 ====\t\t\t\t==== corsairpsu_probe()  hid_device_io_start()   ... unlock driver_input_lock  hid_hw_stop()   kfree(hidraw)\t\t\t__hid_input_report() \t\t\t\t ... acquire driver_input_lock \t\t\t\t hid_report_raw_event() \t\t\t\t  hidraw_report_event() \t\t\t\t   ... access hidraw's list_lock // trigger uaf  Consequently, when corsairpsu_probe() fails and hid_hw_stop() needs to be executed, the io_started flag is first cleared while holding the driver_input_lock to prevent potential race conditions involving input reports.  [1] BUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56 Call Trace:  hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577  hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076  __hid_input_report drivers/hid/hid-core.c:2152 [inline]  hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174  hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286  __usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657  dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005  Allocated by task 10:  hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606  hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277  hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387  corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782  Freed by task 10:  hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662  hid_disconnect drivers/hid/hid-core.c:2362 [inline]  hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407  corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826  Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().  [groeck: Updated subject and description;  call hid_device_io_stop() only if IO has been started]",
  "id": "DEBIAN-CVE-2026-68361",
  "modified": "2026-09-14T16:47:41.264344913Z",
  "published": "2026-08-10T13:20:28.620Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-68361"
    }
  ],
  "upstream": [
    "CVE-2026-68361"
  ]
}