Answer in brief
CVE-2026-97986 records a Unknown severity vulnerability in virtio_input: stop callbacks before unregistering input device. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=271c865161c57cfabca45b93eaa712b19da365bc <8226aeee9b9a94cd699fbb51cb230feff46cfaf2 || >=271c865161c57cfabca45b93eaa712b19da365bc <a3ba86a270dd87460759214046dc7cbd409ac711 || >=271c865161c57cfabca45b93eaa712b19da365bc <5378f7945856a5ed88e6f9850bc7a68f54090135 || >=271c865161c57cfabca45b93eaa712b19da365bc <d7808b37da0a619cf1fa541c2384e783fecc2480 | 8226aeee9b9a94cd699fbb51cb230feff46cfaf2, a3ba86a270dd87460759214046dc7cbd409ac711, 5378f7945856a5ed88e6f9850bc7a68f54090135, d7808b37da0a619cf1fa541c2384e783fecc2480 |
| Linux/Linuxgeneric | 4.1 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio_input: stop callbacks before unregistering input device virtinput_remove() unregisters the input device before resetting the virtio device. virtinput_recv_events() drops vi->lock around input_event(), so clearing vi->ready does not stop a callback that passed the entry check. It can still use vi->idev, requeue buffers and kick the queue. Reset first, as virtinput_freeze() already does. With the preceding core change, reset waits for callbacks before input_unregister_device() can free vi->idev. Recheck vi->ready after taking the lock again: keep draining completed events so an input packet is not truncated, but stop requeueing buffers and kicking the queue. With evdev attached, input_unregister_handle() currently waits for an RCU grace period, which also waits out IRQ callbacks. This masks the lifetime bug on PCI and MMIO, but does not protect sleepable callbacks on other transports.
Quoted source text, attributed separately from HOL analysis.