Linux Kernel UAF via hwmon Gigabyte_Waterforce Race Condition
CVE-2026-68443 Published on August 12, 2026
hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
Products Associated with CVE-2026-68443
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba and below a855f678ba37ef82c4dd22926ad740ecfb8dbedf is affected.
- Version 42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba and below f36e12cc8cfe996d627b8a82bd9df9e43270f6e2 is affected.
- Version 42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba and below 0842e9faab04f784d01125085195031252ff9695 is affected.
- Version 42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba and below ff0c5c53d08274e200b48a4d53aa078265e873cb is affected.
- Version 6.8 is affected.
- Before 6.8 is unaffected.
- Version 6.12.101, <= 6.12.* is unaffected.
- Version 6.18.42, <= 6.18.* is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc5, <= * is unaffected.