CVE-2026-89623: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: stop device IO before hid_hw_stop Quiesce device IO at the start of the devm cleanup callback mcp2221_hid_unregister() so that incoming HID reports cannot race with hardware teardown during probe failure or device removal, addressing a potential use-after-free. Guard the call to hid_device_io_stop() with io_started. On normal removal hid_device_remove() has already cleared io_started before the devres group is released, so an unconditional call would otherwise hit the !io_started path and emit a spurious "io already stopped" warning on every removal. The guard preserves the probe-failure balancing, where io_started is still set after hid_device_io_start(), while staying silent on the normal removal path.
Affected products
- Linux Linux: from 6.6.8, before 6.6.157 (fixed in 6.6.157); from 6.6.8, before 6.12.109 (fixed in 6.12.109); from 6.6.8, before 6.18.50 (fixed in 6.18.50); from 6.6.8, before 7.2.4 (fixed in 7.2.4); from 6.6.8, before 7.3-rc1 (fixed in 7.3-rc1)
Published 2026-09-11. Last modified 2026-09-14.