CVE-2026-89623
In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: stop device IO before hid_hw_stop Quiesce device IO at the start of the devm cleanup callback mcp2221_hid_unregister() so that incoming HID reports cannot race with hardware teardown during probe failure or device removal, addressing a potential use-after-free. Guard the call to hid_device_io_stop() with io_started. On normal removal hid_device_remove() has already cleared io_started before the devres group is released, so an unconditional call would otherwise hit the !io_started path and emit a spurious "io already stopped" warning on every removal. The guard preserves the probe-failure balancing, where io_started is still set after hid_device_io_start(), while staying silent on the normal removal path.
Affected versions
Linux kernel versions
6.6.8
and later are affected. Fixed in
6.6.157
and their respective stable series.
References
5 totalFrequently asked questions
-
What is CVE-2026-89623?
CVE-2026-89623 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.6.8 onward and has been patched in 6.6.157. CVE-2026-89623 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-89623?
Yes. CVE-2026-89623 has been patched. Fixed versions include 6.6.157. If you are running Linux kernel 6.6.8 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-89623 actively exploited?
No. CVE-2026-89623 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.