ReviewHigh

CVE-2026-80559

Linux

In the Linux kernel, the following vulnerability has been resolved: Input: sur40 - fix input device registration ordering In sur40_probe(), input_register_device() was previously called early before the V4L2 video device and vb2_queue components were fully initialized. If userspace opened the input device immediately upon registration, sur40_open() would trigger and start the sur40_poll() worker thread. This worker thread invokes sur40_process_video() and accesses the uninitialized vb2_queue structure, leading to a data race and potential system crash. Furthermore, if V4L2 or video registra...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.08.27
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: Input: sur40 - fix input device registration ordering In sur40_probe(), input_register_device() was previously called early before the V4L2 video device and vb2_queue components were fully initialized. If userspace opened the input device immediately upon registration, sur40_open() would trigger and start the sur40_poll() worker thread. This worker thread invokes sur40_process_video() and accesses the uninitialized vb2_queue structure, leading to a data race and potential system crash. Furthermore, if V4L2 or video registra...

Affected product and versions

Product
Linux
Affected versions
>= e831cd251fb91d6c25352d322743db0d17ea11dd < cd4ecce2fd87760c0ad9a9d28c9fc62ea1dbfd3d, >= e831cd251fb91d6c25352d322743db0d17ea11dd < dab741c9da72102a37cc1020a929051b7c45f9fb, >= e831cd251fb91d6c25352d322743db0d17ea11dd < 764b507be7b51787e1f577ca3bf0bab7efe81ff8, >= e831cd251fb91d6c25352d322743db0d17ea11dd < 3e8ed76a4f3572e637653f0654cccdf617903231, >= e831cd251fb91d6c25352d322743db0d17ea11dd < 83aa12f9f2468a4fbef027c09224dc1011850fb0, >= e831cd251fb91d6c25352d322743db0d17ea11dd < 5c1c5227c93f18cd329dd754b4df5e0e2daece1e, >= e831cd251fb91d6c25352d322743db0d17ea11dd < beb9b0bd6e6e23f5e9e42b7ef890a50f57f1f3aa, >= e831cd251fb91d6c25352d322743db0d17ea11dd < 9da976eb649c9e2f588a4499410e4d8af687925f, >= 4.1
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available