CVE-2025-38494
In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed those checks and allowed invalid paramto be used.
- Linux Linux Kernel
- < 5.4.297, 5.10.241, 5.15.190, 6.1.147, 6.6.100, 6.12.40, 6.15.8, 6.16
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.2% (10th percentile)
- NVD status
- Modified
- Published
- 2025-07-28
CVE-2025-38494 at NVD
1 known exploit for CVE-2025-38494
Proof-of-concept code and exploit modules indexed by Sploitus