PT-2025-25791 · Linux+4 · Linux Kernel+4
Published
2025-05-12
·
Updated
2026-02-05
·
CVE-2025-38016
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A bug in the Linux kernel's HID bpf implementation can cause a cleaned-up SRCU to be accessed after a device has been destroyed, leading to a potential issue. This occurs when a device under the driver has LEDs and the
hid ll driver->request() function is unimplemented. The bug can be triggered when the hidinput led worker() function is scheduled after hid bpf destroy device() and attempts to access the destroyed device. The impact of the bug on other architectures is unclear, but it may cause corruption of memory addresses calculated by SRCU.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu