CVE-2026-68091: Linux
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe failures wacom_parse_and_register() starts HID hardware before registering inputs and initializing pad LEDs/remotes. Those later steps can fail, but their error paths currently release Wacom resources without stopping the HID hardware. Route post-hid_hw_start() failures through hid_hw_stop() before releasing driver resources. This issue was identified during our ongoing static-analysis research while reviewing kernel code.
Affected products
- Linux Linux: from 5.10.210, before 5.10.261 (fixed in 5.10.261); from 5.15.149, before 5.15.212 (fixed in 5.15.212); from 6.1.79, before 6.1.178 (fixed in 6.1.178); from 6.6.18, before 6.6.145 (fixed in 6.6.145); from 4.19.307, before 4.20 (fixed in 4.20); from 5.4.269, before 5.5 (fixed in 5.5); …
Published 2026-08-10. Last modified 2026-08-17.