#VU114166 Input validation error in Linux kernel - CVE-2025-38548
Published: August 18, 2025
Vulnerability identifier: #VU114166
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-38548
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the DECLARE_BITMAP(), send_usb_cmd() and ccp_raw_event() functions in drivers/hwmon/corsair-cpro.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/0db770e2922389753ddbd6663a5516a32b97b743
- https://git.kernel.org/stable/c/2771d2ee3d95700f34e1e4df6a445c90565cd4e9
- https://git.kernel.org/stable/c/3c4bdc8a852e446080adc8ceb90ddd67a56e1bb8
- https://git.kernel.org/stable/c/495a4f0dce9c8c4478c242209748f1ee9e4d5820
- https://git.kernel.org/stable/c/eda5e38cc4dd2dcb422840540374910ef2818494