{"id":"CVE-2026-89626","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89626","summary":"HID: sensor: custom: Fix field sysfs group cleanup on failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: sensor: custom: Fix field sysfs group cleanup on failure\n\nhid_sensor_custom_add_attributes() creates one sysfs group for each\ncustom sensor field. If sysfs_create_group() fails after some groups\nhave already been created, the function returns the error without\nremoving the previously created groups.\n\nAdd a local unwind path to remove the groups that were already created.\nWith enable_sensor exposed only after the field attributes are ready,\nthis path can free sensor_inst->fields without leaving enable_sensor\nable to access pointers into that array.","published":"2026-09-11T19:45:22.769Z","modified":"2026-09-14T03:46:20.396430522Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.12.109"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3789d0802ddb4b3be04062caf4bfadd23496e9a7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/79154fad98ee843e5363940841e2d831503c190a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d96f8958d4469ac02d9c563686cdd968005b944d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f3f37b937a6ea2a00fb5e6189e74f855caa43eb5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89626.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89626"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T03:46:20.396430522Z"}}