---
id: CVE-2026-53037
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  HID: usbhid: fix deadlock in hid_post_reset()

  You can build a USB device that includes a HID component
  and a storage or UAS component
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  HID: usbhid: fix deadlock in hid_post_reset()

  You can build a USB device that includes a HID component
  and a storage or UAS component. The components can be reset
  only…
severity: none
published: '2026-06-24'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53037'
references:
  - url: 'https://git.kernel.org/stable/c/4e900465296ce9fb12ed47dc77389b8dde95bfe0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/56d318ef8766f0deb08517fd8f3007256ea7997d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8df2c1b47ee3cd50fd454f75c7a7e2ae8a6adf72'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/90550af0aad5e75110073c501e4fb42fca20ff80'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ad4505d2ab3aaac6498f17649608e70e80034bf2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b3d16611d7cd78e9d5c6baa19b61b7caf9f1ab5e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c7abd0e6c87441e99c759d40eb6fe589634e3041'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eeceb6f4dd42065fdda3a526a93d08b8fb90fb69'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00125
epssPercentile: 0.01907
ingestedAt: '2026-07-11T19:15:12.264Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

HID: usbhid: fix deadlock in hid_post_reset()

You can build a USB device that includes a HID component
and a storage or UAS component. The components can be reset
only together. That means that hid_pre_reset() and hid_post_reset()
are in the block IO error handling. Hence no memory allocation
used in them may do block IO because the IO can deadlock
on the mutex held while resetting a device and calling the
interface drivers.
Use GFP_NOIO for all allocations in them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
