]> git.ipfire.org Git - thirdparty/linux.git/commit
hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
authorGuenter Roeck <linux@roeck-us.net>
Wed, 8 Jul 2026 01:01:58 +0000 (18:01 -0700)
committerGuenter Roeck <linux@roeck-us.net>
Wed, 8 Jul 2026 03:03:02 +0000 (20:03 -0700)
commitf151d0143ac4e086f92f52328ebdbdc50933d8ef
tree4ede6bc74162d1cb6a6a32fc4977e7ab824ebef1
parent59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e
hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop

Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.

Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().

Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: f3b4b146eb107 ("hwmon: Add driver for NZXT Kraken X and Z series AIO CPU coolers")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
drivers/hwmon/nzxt-kraken3.c