CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64362

highCVSS 7.1covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: HID: lg-g15: cancel pending work on remove to fix a use-after-free lg_g15_data is allocated with devm and holds a work item. The report handlers schedule that work straight from device input. lg_g15_event() and lg_g15_v2_event() do it on the backlight cycle key, and lg_g510_leds_event() does it too. The worker dereferences the lg_g15_data back through container_of. The driver had no remove callback and never cancelled the work. So if a report scheduled the work and the keyboard was then unplugged, devres freed lg_g15_data while the work was still pending or running, and the worker touched freed memory. This is a use-after-free. It is reachable as a race on device unplug. Add a remove callback that cancels the work before devres frees the state. g15->work is only initialized for the models that schedule it (G15, G15 v2, G510). The G13 and Z-10 leave it zeroed, so guard the cancel on g15->work.func to avoid cancelling a work that was never set up. The g15 NULL test mirrors the one already in lg_g15_raw_event().

CSIRTS triage

What
The driver does not properly cancel pending work on device removal, leading to a use-after-free condition.
Who is affected
Deployments using the lg-g15 HID driver.
Urgency
Remediation is advised to prevent potential instability, with no current exploitation reported.
Action
Update to the fixed driver version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64362

Get an email if CVE-2026-64362 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64362

CVE.org record

Embed the live status

CVE-2026-64362 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64362 status](https://www.csirts.com/badge/CVE-2026-64362)](https://www.csirts.com/cve/CVE-2026-64362)