CVE-2026-53037 Details
Description
In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix deadlock in hid_post_reset() You can build a USB device that includes a HID component and a storage or UAS component. The components can be reset only together. That means that hid_pre_reset() and hid_post_reset() are in the block IO error handling. Hence no memory allocation used in them may do block IO because the IO can deadlock on the mutex held while resetting a device and calling the interface drivers. Use GFP_NOIO for all allocations in them.
A deadlock vulnerability has been identified in the Linux kernel's handling of USB devices that include both Human Interface Device (HID) and storage components. This issue arises because the HID components can only be reset in conjunction with the storage components, leading to a potential deadlock. The problem occurs in the block I/O error handling functions 'hid_pre_reset()' and 'hid_post_reset()', where memory allocations can inadvertently cause block I/O operations that deadlock on a mutex. The vulnerability affects several versions of the Linux kernel.
The vulnerability has been addressed by modifying the memory allocation in the 'hid_post_reset()' function to use 'GFP_NOIO', which prevents block I/O operations that could cause a deadlock. Users should apply the latest patches available in the Linux kernel stable tree to mitigate this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/4e900465296ce9fb12ed47dc77389b8dde95bfe0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/56d318ef8766f0deb08517fd8f3007256ea7997d | kernel.org | Patch |
| https://git.kernel.org/stable/c/8df2c1b47ee3cd50fd454f75c7a7e2ae8a6adf72 | kernel.org | Patch |
| https://git.kernel.org/stable/c/90550af0aad5e75110073c501e4fb42fca20ff80 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ad4505d2ab3aaac6498f17649608e70e80034bf2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b3d16611d7cd78e9d5c6baa19b61b7caf9f1ab5e | kernel.org | Patch |
| https://git.kernel.org/stable/c/c7abd0e6c87441e99c759d40eb6fe589634e3041 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eeceb6f4dd42065fdda3a526a93d08b8fb90fb69 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.5, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | New CVE Received | kernel.org |