PT-2026-68428 · Linux · Linux Kernel

CVE-2026-64595

·

Published

2026-08-06

·

Updated

2026-08-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the hid-lenovo-go driver where the hid go cfg remove() function fails to drain delayed work. The hid go cfg probe() function initializes drvdata.go cfg setup and schedules it to run after a 2 ms delay. The cfg setup() function then dereferences drvdata.hdev to issue MCU command requests. If the device is unbound during this 2 ms window—such as during a probe failure or a rapid module removal—the work executes after hid destroy device() has released the hdev struct. This results in cfg setup() using a stale drvdata.hdev pointer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64595
OPENSUSE-SU-2026:11476-1

Affected Products

Linux Kernel