PT-2025-30778 · Linux+1 · Linux Kernel+1

Published

2025-06-24

·

Updated

2025-11-20

·

CVE-2025-38378

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue was identified in the appletb kbd probe function within the HID subsystem. The vulnerability occurs when a timer, kbd->inactivity timer, remains active after the associated memory is freed, leading to a potential crash when the timer expires and attempts to access the freed memory. The root cause is the failure to disarm the timer on failure paths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-09243
CVE-2025-38378

Affected Products

Astra Linux
Linux Kernel