# CVE-2026-89626

## Summary

- **CVE ID:** CVE-2026-89626
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

HID: sensor: custom: Fix field sysfs group cleanup on failure

hid_sensor_custom_add_attributes() creates one sysfs group for each
custom sensor field. If sysfs_create_group() fails after some groups
have already been created, the function returns the error without
removing the previously created groups.

Add a local unwind path to remove the groups that were already created.
With enable_sensor exposed only after the field attributes are ready,
this path can free sensor_inst->fields without leaving enable_sensor
able to access pointers into that array.

## Affected Products

- Linux — Linux (4a7de0519df5e8fb89cef6ee062330ffe4b50a4d)
- Linux — Linux (4.1)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/79154fad98ee843e5363940841e2d831503c190a)
- [CNA](https://git.kernel.org/stable/c/f3f37b937a6ea2a00fb5e6189e74f855caa43eb5)
- [CNA](https://git.kernel.org/stable/c/d96f8958d4469ac02d9c563686cdd968005b944d)
- [CNA](https://git.kernel.org/stable/c/3789d0802ddb4b3be04062caf4bfadd23496e9a7)
- [CNA](https://git.kernel.org/stable/c/416194933af63bd58d03b7605b1ebc1711186838)
- [CNA](https://git.kernel.org/stable/c/d0e15091e88d18e30b67daf85b88f6528bb9bf41)
- [CNA](https://git.kernel.org/stable/c/10b05fafff932e325896d59dde40938954ab4577)
- [CNA](https://git.kernel.org/stable/c/2409779f3096fcef41bcf57b5f4887d0fa0dc8dd)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 28.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._