
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-43049 is a use-after-free (UAF) vulnerability in the Linux kernel's HID: logitech-hidpp driver that can allow a local attacker to execute arbitrary code with kernel privileges. The flaw affects the Logitech G920 Driving Force Racing Wheel for Xbox One driver and was published on May 1, 2026. Affected kernel versions span from 5.4.1 up to (but not including) 6.12.81, 6.13 up to 6.18.22, and 6.19 up to 6.19.12, as well as 7.0 release candidates. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Red Hat).
The root cause is a use-after-free condition (CWE-416) in the logitech-hidpp kernel driver. When force feedback initialization fails during probing of the Logitech G920 device, the driver returns an error code before properly tearing down the userspace infrastructure — specifically the sysfs entries and /dev/input device node. This leaves dangling references to freed memory; if userspace ignores the error and continues interacting with these stale references, a UAF condition is triggered. The fix changes the driver behavior to treat force feedback initialization failure as a non-fatal warning, returning success and keeping the device functional (minus force feedback), thereby ensuring the infrastructure is never left in a partially torn-down state (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a local user with low privileges and access to the affected HID device interface to achieve arbitrary code execution at the kernel level, resulting in high confidentiality, integrity, and availability impact. An attacker could leverage kernel-level code execution to escalate privileges to root, access sensitive system data, corrupt kernel memory, or cause a system crash. The scope is limited to the local system, but a successful exploit could serve as a stepping stone for broader lateral movement within a compromised environment (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (3rd percentile), indicating a very low probability of exploitation in the near term. Exploitation requires local access to the system and physical or logical access to the affected Logitech HID device, which significantly limits the attack surface.
Patches have been committed to the Linux kernel stable trees. Users should update to kernel versions 6.12.81 or later, 6.18.22 or later, 6.19.12 or later, or 7.0 (stable release) to remediate the vulnerability (GitHub Advisory, Red Hat Bugzilla). Distribution-specific kernel updates from vendors such as Red Hat should be applied as they become available (Red Hat). As a temporary workaround, administrators can restrict access to Logitech HID devices or unload/blacklist the hid-logitech-hidpp kernel module if the device is not in use.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."