CVE-2026-68360: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
hwmon: (corsair-cpro) Stop device IO before calling hidhwstop
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.150.1-1 - Configuration
In the driver probe function, stop device IO by calling hid_device_io_stop() immediately following the execution of hid_device_io_start(), and ensure this occurs before calling hid_hw_stop().
Linux HID hwmon driver (corsair-cpro) probe function call order = call hid_device_io_stop() immediately after hid_device_io_start(); call hid_hw_stop() only after hid_device_io_stop()
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68360?
The severity of CVE-2026-68360 is rated at 43, indicating a moderate risk associated with this vulnerability.
What type of vulnerability is CVE-2026-68360?
CVE-2026-68360 is classified as a race condition vulnerability within the Linux kernel.
How do I fix CVE-2026-68360?
To fix CVE-2026-68360, ensure that the Linux kernel is updated to a version where the vulnerability has been patched.
Which component is affected by CVE-2026-68360?
CVE-2026-68360 specifically affects the hwmon subsystem for the corsair-cpro device.
What are the consequences of CVE-2026-68360?
The consequences of CVE-2026-68360 include potential instability and unexpected behavior due to the race condition between hid_input_report() and device IO.