MEDIUM

CVE-2026-53037

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

HID: usbhid: fix deadlock in hid_post_reset()

You can build a USB device that includes a HID component
and a storage or UAS component. The components can be reset
only together. That means that hid_pre_reset() and hid_post_reset()
are in the block IO error handling. Hence no memory allocation
used in them may do block IO because the IO can deadlock
on the mutex held while resetting a device and calling the
interface drivers.
Use GFP_NOIO for all allocations in them.

Summary dbcve.org

A deadlock vulnerability exists in the Linux kernel's USB HID driver (hid_post_reset and hid_pre_reset functions). When a USB device contains both HID and storage/UAS components that must be reset together, memory allocations using standard flags can trigger block IO, which deadlocks on a mutex held during device reset in the error handling path. The fix requires using GFP_NOIO for all allocations in these functions to prevent block IO during the reset sequence.

Mitigation

Apply the kernel patch to change memory allocation flags from GFP_KERNEL or similar to GFP_NOIO in hid_pre_reset() and hid_post_reset() functions. This prevents block IO during the device reset error handling path, eliminating the deadlock condition.

Patch Commit

Weakness (CWE)

CWE-667 Improper Locking

EPSS Score

0.1%
Probability of exploitation in next 30 days
0.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE