CVE-2026-80766 Overview
CVE-2026-80766 is a use-after-free vulnerability in the Linux kernel's HID uclogic driver, which supports Ugee-based graphics tablets. The flaw resides in the uclogic_remove() teardown path, where a pen in-range timer can be re-armed by an in-flight HID report after timer_delete_sync() has already cancelled it. When the timer callback subsequently fires, it dereferences the freed pen_input device memory in timer-softirq context. The kernel maintainers resolved the issue by switching to timer_shutdown_sync(), which prevents further re-arming and guarantees the timer is dead before hid_hw_stop() frees the input device.
Critical Impact
A race between HID report delivery and device removal can cause kernel memory corruption in softirq context, potentially leading to denial of service or local privilege escalation on systems with affected Ugee-family graphics tablets.
Affected Products
- Linux kernel HID subsystem — drivers/hid/hid-uclogic-core.c
- Ugee-based graphics tablets handled by the uclogic driver
- Multiple stable kernel branches (see referenced Git commits for backport scope)
Discovery Timeline
- 2026-09-04 - CVE-2026-80766 published to NVD
- 2026-09-04 - Last updated in NVD database
Technical Details for CVE-2026-80766
Vulnerability Analysis
The uclogic driver maintains an inrange_timer used to signal when a stylus leaves proximity of the tablet surface. During module or device removal, uclogic_remove() calls timer_delete_sync(&drvdata->inrange_timer) followed by hid_hw_stop(hdev). The synchronous delete only guarantees the timer is idle at that instant; it does not prevent subsequent re-arming.
Between these two calls, uclogic_raw_event_pen() continues to process pen reports arriving over the transport. Each report where pen->inrange == UCLOGIC_PARAMS_PEN_INRANGE_NONE invokes mod_timer(&drvdata->inrange_timer, jiffies + msecs_to_jiffies(100)), re-arming the cancelled timer.
After uclogic_remove() returns, the devm-allocated drvdata is freed and hid_hw_stop() has already released the input device that drvdata->pen_input referenced. When the re-armed timer fires roughly 100 ms later, uclogic_inrange_timeout() dereferences the freed input structure, producing a use-after-free ([CWE-416]) executed in timer-softirq context.
Root Cause
The root cause is an incorrect teardown ordering assumption. timer_delete_sync() does not block future mod_timer() calls, so any code path still able to submit reports can silently resurrect the timer. Swapping the two calls does not fix the issue because hidinput_disconnect() would then free pen_input while a previously armed timer is still pending.
Attack Vector
Exploitation requires triggering device removal while HID reports are actively arriving. This can occur during physical unplug of a USB tablet, driver unbind through sysfs, or malicious USB device emulation that races report delivery against a bind/unbind cycle. Local attackers with the ability to attach USB devices, or in constrained multi-user scenarios where a HID device is present, could deterministically drive the race. Successful exploitation corrupts kernel memory during softirq execution, with impact ranging from a kernel oops (denial of service) to potential privilege escalation depending on heap layout at the moment the freed input device is dereferenced.
No public proof-of-concept has been published. The fix, described in the referenced kernel Git commits, replaces timer_delete_sync() with timer_shutdown_sync(), which cancels the timer, waits for any running callback while pen_input is still valid, and silently ignores any subsequent mod_timer() from in-flight reports.
Detection Methods for CVE-2026-80766
Indicators of Compromise
- Kernel oops or general protection fault messages referencing uclogic_inrange_timeout in dmesg, particularly following USB device disconnect events.
- KASAN (Kernel Address Sanitizer) reports flagging a use-after-free in the HID uclogic code path during device removal.
- Unexpected kernel panics correlated with graphics tablet unplug, driver unbind, or module unload operations.
Detection Strategies
- Enable KASAN and lockdep on test kernels to surface the race deterministically during USB unbind stress testing on affected drivers.
- Monitor kernel ring buffer telemetry for softirq faults referencing HID input structures on hosts running vulnerable kernel versions.
- Inventory running kernel builds against the fixed commits (506fd50, 849e537, 9d77ac8, dc5108f, e750cdb, f13d0a0, f1b3ca0, f402433) to identify unpatched systems.
Monitoring Recommendations
- Forward dmesg and journald kernel logs to centralized log analytics and alert on BUG:, KASAN:, and Oops: strings referencing hid-uclogic or uclogic_inrange_timeout.
- Track USB device attach/detach events on endpoints where graphics tablets are used, correlating them with subsequent kernel instability.
- Include kernel version and patch level in endpoint asset inventory to prioritize remediation of hosts running affected builds.
How to Mitigate CVE-2026-80766
Immediate Actions Required
- Apply vendor-provided kernel updates that include the timer_shutdown_sync() fix referenced in the upstream stable Git commits.
- If patching is not immediately possible, unload the hid-uclogic module on systems that do not require Ugee tablet support using modprobe -r hid_uclogic.
- Restrict physical and logical USB access on multi-user or kiosk systems where untrusted users could attach HID devices.
Patch Information
The upstream fix replaces timer_delete_sync() with timer_shutdown_sync() in uclogic_remove(). Backports have been merged across multiple stable branches; refer to the following commits: Kernel Git Commit 506fd50, Kernel Git Commit 849e537, Kernel Git Commit 9d77ac8, Kernel Git Commit dc5108f, Kernel Git Commit e750cdb, Kernel Git Commit f13d0a0, Kernel Git Commit f1b3ca0, and Kernel Git Commit f402433. Consume the update through your distribution's kernel package channel.
Workarounds
- Blacklist the hid_uclogic module on hosts that do not use supported Ugee tablets by adding blacklist hid_uclogic to a file under /etc/modprobe.d/.
- Avoid hot-unplug of affected tablets on production systems until the patched kernel is installed; power the host down before disconnecting the device where practical.
- Enforce USB device allow-listing via USBGuard or equivalent controls to prevent untrusted HID devices from being attached.
# Verify running kernel and prevent uclogic driver from loading until patched
uname -r
sudo modprobe -r hid_uclogic
echo 'blacklist hid_uclogic' | sudo tee /etc/modprobe.d/cve-2026-80766.conf
sudo update-initramfs -u
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.