CVE-2026-90041
CVE CVE-2026-90041EUVD EUVD-2026-80649Published 2026-09-16T10:33:39.000ZLast changed 2026-09-21T13:15:16.000ZCVSS 8.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list on probe failure sony_input_configured() adds some controllers to sony_device_list before HID core registers their input devices. input_register_device() can fail after the callback returns successfully. sony_probe() then observes that HID_CLAIMED_INPUT is clear and unwinds, but only stops the HID hardware. The devres-managed sony_sc is freed while its list node remains linked, so the next matching controller traverses freed memory. Initialize the list node and device ID to inactive states. Make list removal idempotent and run the driver-private cleanup on every probe failure path. This also makes a second cleanup safe when sony_input_configured() already unwound a partial initialization before sony_probe() handles the missing input claim. Found by 0sec (https://0sec.ai) using automated source analysis; verified against the HID input registration and probe unwind paths.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.2.5; 4f967f6d73746f66514528cc1191025f0b5d69b3 <b84544ef00a27e8081498d33af7dac33b6cb8418; 4f967f6d73746f66514528cc1191025f0b5d69b3 <3b4709e4864908bb06c48c500cc8db8d3d55d139; patch: 6.18.51; 4.10; 4f967f6d73746f66514528cc1191025f0b5d69b3 <d044d796e2a369c6051c7e83dce88c7baa2494d4; patch: 0; patch: 6.12.111; patch: 7.3-rc1; 4f967f6d73746f66514528cc1191025f0b5d69b3 <7c65699a3a311198a07659a614fe64d45924839e
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.