CVE-2026-68087EPSS p6.2%
CVE-2026-68087CVE-2026-68087
Description
In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()
wacom_wac_queue_flush() is called via the .raw_event callback
(wacom_raw_event → wacom_wac_pen_serial_enforce → wacom_wac_queue_flush).
For USB HID devices, this callback is invoked from hid_irq_in(), which
is a URB completion handler running in atomic context. Using GFP_KERNEL
in this path can sleep, leading to a "scheduling while atomic" bug.
Use GFP_ATOMIC instead. The existing code already handles allocation
failure by skipping the fifo entry and continuing.
Scoring
| EPSS | 0.17% probability of exploitation · percentile 6.2% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-10 |