CVE-2026-64363: HID: appleir: fix UAF on pending key_up_timer in remove()
HID: appleir: fix UAF on pending keyuptimer in remove()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Compensating control
Update the HID appleir driver teardown logic to add a `removing` flag on `struct appleir`, set it under the spinlock before teardown, make `appleir_raw_event()` and `key_up_tick()` exit when the flag is set, and use `timer_shutdown_sync()` after `hid_hw_stop()` so in-flight callbacks cannot dereference `input_dev` or re-arm the timer.
Event History
Frequently Asked Questions
What is the vulnerability ID of the issue described?
The vulnerability ID of the issue described is CVE-2026-64363.
What is the severity level of CVE-2026-64363?
The severity level of CVE-2026-64363 is medium with a score of 5.5.
What type of vulnerability is CVE-2026-64363?
CVE-2026-64363 is a use-after-free vulnerability in the HID: appleir driver.
Which software is affected by CVE-2026-64363?
CVE-2026-64363 affects the Linux Kernel and Microsoft azl3 kernel version 6.6.144.1-1.
How can I mitigate CVE-2026-64363?
To mitigate CVE-2026-64363, ensure that you update to the latest patched version of the Linux kernel.