← All Advisories

CVE-2026-90041

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-90041

Key Details

CVECVE-2026-90041
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

HID: sony: clean up device list on probe failure

sony_input_configured() adds some controllers to sony_device_list before

HID core registers their input devices. input_register_device() can fail

after the callback returns successfully. sony_probe() then observes that

HID_CLAIMED_INPUT is clear and unwinds, but only stops the HID hardware.

The devres-managed sony_sc is freed while its list node remains linked, so

the next matching controller traverses freed memory.

Initialize the list node and device ID to inactive states. Make list

removal idempotent and run the driver-private cleanup on every probe

failure path. This also makes a second cleanup safe when

sony_input_configured() already unwound a partial initialization before

sony_probe() handles the missing input claim.

Found by 0sec (https://0sec.ai) using automated source analysis;

verified against the HID input registration and probe unwind paths. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90041
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90041