CVE-2026-53037
Description
In the Linux kernel, the following vulnerability has been resolved:
HID: usbhid: fix deadlock in hid_post_reset()
You can build a USB device that includes a HID component
and a storage or UAS component. The components can be reset
only together. That means that hid_pre_reset() and hid_post_reset()
are in the block IO error handling. Hence no memory allocation
used in them may do block IO because the IO can deadlock
on the mutex held while resetting a device and calling the
interface drivers.
Use GFP_NOIO for all allocations in them.
Summary dbcve.org
A deadlock vulnerability exists in the Linux kernel's USB HID driver (hid_post_reset and hid_pre_reset functions). When a USB device contains both HID and storage/UAS components that must be reset together, memory allocations using standard flags can trigger block IO, which deadlocks on a mutex held during device reset in the error handling path. The fix requires using GFP_NOIO for all allocations in these functions to prevent block IO during the reset sequence.
Mitigation
Apply the kernel patch to change memory allocation flags from GFP_KERNEL or similar to GFP_NOIO in hid_pre_reset() and hid_post_reset() functions. This prevents block IO during the device reset error handling path, eliminating the deadlock condition.