CVE-2026-64363: HID: appleir: fix UAF on pending key_up_timer in remove()
Published Jul 25, 2026
·Updated
HID: appleir: fix UAF on pending keyuptimer in remove()
Affected Software
11 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Linux Linux kernel>=3.10<5.10.261
Linux Linux kernel>=5.11<5.15.212
Linux Linux kernel>=5.16<6.1.178
Linux Linux kernel>=6.2<6.6.145
Linux Linux kernel>=6.7<6.12.97
Linux Linux kernel>=6.13<6.18.39
Linux Linux kernel>=6.19<7.1.4
Linux Linux kernel=7.2-rc1
Linux Linux kernel=7.2-rc2
Remediation
Event History
Jul 25, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
Description
Data Sourced
via NVD·10:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 26, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:09 AM
Affected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID of the issue described?
The vulnerability ID of the issue described is CVE-2026-64363.
2
What is the severity level of CVE-2026-64363?
The severity level of CVE-2026-64363 is medium with a score of 5.5.
3
What type of vulnerability is CVE-2026-64363?
CVE-2026-64363 is a use-after-free vulnerability in the HID: appleir driver.
4
Which software is affected by CVE-2026-64363?
CVE-2026-64363 affects the Linux Kernel and Microsoft azl3 kernel version 6.6.144.1-1.
5
How can I mitigate CVE-2026-64363?
To mitigate CVE-2026-64363, ensure that you update to the latest patched version of the Linux kernel.