VDB

DEBIAN-CVE-2025-38494

DEBIAN-CVE-2025-38494 PUBLISHED CVSS 7.800000190734863 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed those checks and allowed invalid paramto be used.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:14linux6.12.38-1, 6.12.43-1, 6.12.43-1~bpo12+1
Debian:12linux6.1.66-1, 6.1.106-1, 6.1.106-3
Debian:11linux5.10.209-2, 5.10.179-5, 5.10.191-1
Debian:13linux0, 0, 6.12.38-1
Debian:11linux-6.16.1.137-1~deb11u1, 6.1.140-1~deb11u1, 6.1.148-1~deb11u1

Timeline

  • Jul 28, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›