{"id":"CVE-2026-90331","published":"2026-09-17T17:17:31.610","lastModified":"2026-09-17T17:17:31.610","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: asus: refactor the two workqueues and init sequence\n\nMultiple issues have been found within the hid-asus driver:\n- unchecked size in asus_raw_event()\n- unclean teardown of asus_probe on failure\n- possible use-after-free in asus_probe\n- multiple workqueue used for jobs where one was enough\n- sleeping calls in atomic context\n- packets of incorrect size being sent to the keyboard controller\n\nJoin the two workqueues into one reusing the stopping mechanism\nof the brightness workqueue, use the joined workqueue to also\nmove the asus_wmi_send_event() sleeping call away from atomic\ncontext and add a size check in asus_raw_event().","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/47669bec44fe12fe2c7adf2b299e980d7935a2ce","tags":[]},{"url":"https://git.kernel.org/stable/c/744b3f930c1173ad57f49b614fc875d8d2715396","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}