I
n the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed those checks and allowed invalid paramto be used.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
26 Jan 2026, 20:47
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| References | () https://git.kernel.org/stable/c/0e5017d84d650ca0eeaf4a3fe9264c5dbc886b81 - Patch | |
| References | () https://git.kernel.org/stable/c/19d1314d46c0d8a5c08ab53ddeb62280c77698c0 - Patch | |
| References | () https://git.kernel.org/stable/c/40e25aa7e4e0f2440c73a683ee448e41c7c344ed - Patch | |
| References | () https://git.kernel.org/stable/c/a62a895edb2bfebffa865b5129a66e3b4287f34f - Patch | |
| References | () https://git.kernel.org/stable/c/c2ca42f190b6714d6c481dfd3d9b62ea091c946b - Patch | |
| References | () https://git.kernel.org/stable/c/d18f63e848840100dbc351a82e7042eac5a28cf5 - Patch | |
| References | () https://git.kernel.org/stable/c/dd8e8314f2ce225dade5248dcfb9e2ac0edda624 - Patch | |
| References | () https://git.kernel.org/stable/c/f10923b8d32a473b229477b63f23bbd72b1e9910 - Patch | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory | |
| CPE | cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:* |
|
| First Time |
Debian
Linux linux Kernel Linux Debian debian Linux |
|
| CWE | NVD-CWE-noinfo |
03 Nov 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
28 Aug 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-28 12:15
Updated : 2026-01-26 20:47
NVD link : CVE-2025-38494
Mitre link : CVE-2025-38494
CVE.ORG link : CVE-2025-38494
JSON object : View
Products Affected
CWE