CVE-2026-89623

In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: stop device IO before hid_hw_stop Quiesce device IO at the start of the devm cleanup callback mcp2221_hid_unregister() so that incoming HID reports cannot race with hardware teardown during probe failure or device removal, addressing a potential use-after-free. Guard the call to hid_device_io_stop() with io_started. On normal removal hid_device_remove() has already cleared io_started before the devres group is released, so an unconditional call would otherwise hit the !io_started path and emit a spurious "io already stopped" warning on every removal. The guard preserves the probe-failure balancing, where io_started is still set after hid_device_io_start(), while staying silent on the normal removal path.

Package Linux Kernel
Published 2026-09-11
Last modified 2026-09-14
Patch available
Yes

Frequently asked questions

  • What is CVE-2026-89623?

    CVE-2026-89623 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.6.8 onward and has been patched in 6.6.157. CVE-2026-89623 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-89623?

    Yes. CVE-2026-89623 has been patched. Fixed versions include 6.6.157. If you are running Linux kernel 6.6.8 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-89623 actively exploited?

    No. CVE-2026-89623 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.