CVE-2026-43049
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-43049 is a use-after-free (UAF) vulnerability in the Linux kernel's HID: logitech-hidpp driver that can allow a local attacker to execute arbitrary code with kernel privileges. The flaw affects the Logitech G920 Driving Force Racing Wheel for Xbox One driver and was published on May 1, 2026. Affected kernel versions span from 5.4.1 up to (but not including) 6.12.81, 6.13 up to 6.18.22, and 6.19 up to 6.19.12, as well as 7.0 release candidates. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is a use-after-free condition (CWE-416) in the logitech-hidpp kernel driver. When force feedback initialization fails during probing of the Logitech G920 device, the driver returns an error code before properly tearing down the userspace infrastructure — specifically the sysfs entries and /dev/input device node. This leaves dangling references to freed memory; if userspace ignores the error and continues interacting with these stale references, a UAF condition is triggered. The fix changes the driver behavior to treat force feedback initialization failure as a non-fatal warning, returning success and keeping the device functional (minus force feedback), thereby ensuring the infrastructure is never left in a partially torn-down state (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a local user with low privileges and access to the affected HID device interface to achieve arbitrary code execution at the kernel level, resulting in high confidentiality, integrity, and availability impact. An attacker could leverage kernel-level code execution to escalate privileges to root, access sensitive system data, corrupt kernel memory, or cause a system crash. The scope is limited to the local system, but a successful exploit could serve as a stepping stone for broader lateral movement within a compromised environment (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (3rd percentile), indicating a very low probability of exploitation in the near term. Exploitation requires local access to the system and physical or logical access to the affected Logitech HID device, which significantly limits the attack surface.

Mitigation and workarounds

Patches have been committed to the Linux kernel stable trees. Users should update to kernel versions 6.12.81 or later, 6.18.22 or later, 6.19.12 or later, or 7.0 (stable release) to remediate the vulnerability (GitHub Advisory, Red Hat Bugzilla). Distribution-specific kernel updates from vendors such as Red Hat should be applied as they become available (Red Hat). As a temporary workaround, administrators can restrict access to Logitech HID devices or unload/blacklist the hid-logitech-hidpp kernel module if the device is not in use.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Affected

sid

linux: 6.19.12-1

Fixed

trixie

linux: 6.12.85-1

Fixed

Ubuntu

Fixed

bionic

linux

Not Affected

bionic (esm-infra)

linux-hwe-5.4

Affected

bionic (fips-updates)

linux-fips

Not Affected

bionic (fips)

linux-fips

Not Affected

devel

linux

Not Affected

focal

linux-azure-fde-5.15

Not Affected

focal (esm-infra)

linux

Affected

focal (fips-updates)

linux-fips

Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-89771HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoNoSep 11, 2026
CVE-2026-89763HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-5.4
NoYesSep 11, 2026
CVE-2026-89760HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.14
NoNoSep 11, 2026
CVE-2026-89759MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • kernel-debug-modules
NoYesSep 11, 2026
CVE-2026-89757LOW3.6
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management