CVE-2026-68361: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop

Published Aug 10, 2026
·
Updated

hwmon: (corsair-psu) Stop device IO before calling hidhwstop

Affected Software

2 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.143.1-1<6.6.150.1-1
6.6.150.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.150.1-1
  2. Configuration

    Ensure that when corsairpsu_probe() fails after IO has been started, hid_device_io_stop() is called before hid_hw_stop(), to clear the io_started flag while holding driver_input_lock and prevent the hid_input_report vs. disconnect UAF race.

    Linux kernel HID core (drivers/hid/hid-core.c) Stop device IO before calling hid_hw_stop() = Apply code change: call hid_device_io_stop() before hid_hw_stop() when probe fails

Event History

Aug 10, 2026
CVE Published
via MITRE·12:03 PM
Data Sourced
via MITRE·12:03 PM
Description
Data Sourced
via NVD·01:20 PM
Description
Aug 11, 2026
Data Sourced
via Microsoft·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:15 AM
Affected Software
Updated
via Microsoft·08:15 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the risk level of CVE-2026-68361?

CVE-2026-68361 has a risk level of 40.

2

What does CVE-2026-68361 affect?

CVE-2026-68361 affects the Linux kernel, specifically the hwmon component related to corsair-psu.

3

What type of vulnerabilities are associated with CVE-2026-68361?

CVE-2026-68361 is associated with Use After Free and Race Condition vulnerabilities.

4

How can I mitigate CVE-2026-68361?

Mitigation for CVE-2026-68361 involves updating the Linux kernel to the patched version.

5

What is the main issue described in CVE-2026-68361?

CVE-2026-68361 describes a race condition in the hid_hw_stop function that fails to stop device IO.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203