CVE-2026-89626: Linux
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix field sysfs group cleanup on failure hid_sensor_custom_add_attributes() creates one sysfs group for each custom sensor field. If sysfs_create_group() fails after some groups have already been created, the function returns the error without removing the previously created groups. Add a local unwind path to remove the groups that were already created. With enable_sensor exposed only after the field attributes are ready, this path can free sensor_inst->fields without leaving enable_sensor able to access pointers into that array.
Affected products
- Linux Linux: from 4.1, before 5.10.270 (fixed in 5.10.270); from 5.11, before 5.15.221 (fixed in 5.15.221); from 5.16, before 6.1.188 (fixed in 6.1.188); from 6.2, before 6.6.157 (fixed in 6.6.157); from 6.7, before 6.12.109 (fixed in 6.12.109); from 6.13, before 6.18.50 (fixed in 6.18.50); …
Published 2026-09-11. Last modified 2026-09-14.