{"id":"CVE-2026-80559","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-80559","summary":"Input: sur40 - fix input device registration ordering","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: sur40 - fix input device registration ordering\n\nIn sur40_probe(), input_register_device() was previously called early before\nthe V4L2 video device and vb2_queue components were fully initialized. If\nuserspace opened the input device immediately upon registration, sur40_open()\nwould trigger and start the sur40_poll() worker thread. This worker thread\ninvokes sur40_process_video() and accesses the uninitialized vb2_queue\nstructure, leading to a data race and potential system crash.\n\nFurthermore, if V4L2 or video registration failed after input_register_device()\nsucceeded, the error path fell through to calling input_free_device() on a\nsuccessfully registered device instead of input_unregister_device(), corrupting\ninput core state.\n\nMove input_register_device() to the very end of sur40_probe(). This ensures\nthe V4L2 and video queue structures are fully initialized before polling can\nstart, and naturally resolves the error path bug since input_free_device()\nis now only called when input registration has not yet occurred.\n\nTo maintain strict LIFO (Last-In, First-Out) teardown ordering, also move\ninput_unregister_device() to the very beginning of sur40_disconnect(). This\nguarantees that the input polling worker thread is stopped before V4L2\nvideo components or control handlers are unregistered.","published":"2026-08-26T14:37:25.371Z","modified":"2026-08-28T03:47:29.023052688Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.266"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3e8ed76a4f3572e637653f0654cccdf617903231"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5c1c5227c93f18cd329dd754b4df5e0e2daece1e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/764b507be7b51787e1f577ca3bf0bab7efe81ff8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/83aa12f9f2468a4fbef027c09224dc1011850fb0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9da976eb649c9e2f588a4499410e4d8af687925f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/beb9b0bd6e6e23f5e9e42b7ef890a50f57f1f3aa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cd4ecce2fd87760c0ad9a9d28c9fc62ea1dbfd3d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dab741c9da72102a37cc1020a929051b7c45f9fb"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80559.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80559"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T03:47:29.023052688Z"}}