CVE-2026-97987

Source
https://cve.org/CVERecord?id=CVE-2026-97987
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97987.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97987
Downstream
Published
2026-09-25T10:23:21Z
Modified
2026-09-26T03:48:42Z
Summary
virtio_input: reset device if input_register_device() fails
Details

In the Linux kernel, the following vulnerability has been resolved:

virtio_input: reset device if input_register_device() fails

Probe marks the device DRIVER_OK with virtio_device_ready() before calling input_register_device(). If registration fails, the error path cleared vi->ready and called del_vqs() while the device was still live, so the device could keep DMA to queues that were already torn down.

Match remove/freeze: call virtio_reset_device() on that path before tearing down the virtqueues.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97987.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
271c865161c57cfabca45b93eaa712b19da365bc
Fixed
9a7e107734137f098f9b81e5615aa5a02c5395c7
Fixed
8407da8974326c1ffdfe6a5a9bfc8fed3212bbdf
Fixed
668ebfea7ba623450b12fdeaa0d080464d0c0a14
Fixed
81489b32a21c9360f8750d1fb600155d27452e19

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97987.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97987.json"