SB2025081869 - Input validation error in Linux kernel hid driver
Published: August 18, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-38540)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the HID_USB_DEVICE() function in drivers/hid/hid-quirks.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1b297ab6f38ca60a4ca7298b297944ec6043b2f4
- https://git.kernel.org/stable/c/2b0931eee48208c25bb77486946dea8e96aa6a36
- https://git.kernel.org/stable/c/35f1a5360ac68d9629abbb3930a0a07901cba296
- https://git.kernel.org/stable/c/3ce1d87d1f5d80322757aa917182deb7370963b9
- https://git.kernel.org/stable/c/54bae4c17c11688339eb73a04fd24203bb6e7494
- https://git.kernel.org/stable/c/7ac00f019698f614a49cce34c198d0568ab0e1c2
- https://git.kernel.org/stable/c/a2a91abd19c574b598b1c69ad76ad9c7eedaf062
- https://git.kernel.org/stable/c/c72536350e82b53a1be0f3bfdf1511bba2827102