{"id":"CVE-2026-97986","published":"2026-09-25T11:17:26.683","lastModified":"2026-09-25T11:17:26.683","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_input: stop callbacks before unregistering input device\n\nvirtinput_remove() unregisters the input device before resetting the\nvirtio device. virtinput_recv_events() drops vi->lock around input_event(),\nso clearing vi->ready does not stop a callback that passed the entry check.\nIt can still use vi->idev, requeue buffers and kick the queue.\n\nReset first, as virtinput_freeze() already does. With the preceding core\nchange, reset waits for callbacks before input_unregister_device() can\nfree vi->idev. Recheck vi->ready after taking the lock again: keep draining\ncompleted events so an input packet is not truncated, but stop requeueing\nbuffers and kicking the queue.\n\nWith evdev attached, input_unregister_handle() currently waits for an RCU\ngrace period, which also waits out IRQ callbacks. This masks the lifetime\nbug on PCI and MMIO, but does not protect sleepable callbacks on other\ntransports.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/5378f7945856a5ed88e6f9850bc7a68f54090135","tags":[]},{"url":"https://git.kernel.org/stable/c/8226aeee9b9a94cd699fbb51cb230feff46cfaf2","tags":[]},{"url":"https://git.kernel.org/stable/c/a3ba86a270dd87460759214046dc7cbd409ac711","tags":[]},{"url":"https://git.kernel.org/stable/c/d7808b37da0a619cf1fa541c2384e783fecc2480","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}