Sploitus

CVE-2025-38495

1 known exploit for CVE-2025-38495

In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated buffer not account for that extra byte, meaning that instead of having 8 guaranteed bytes for implement to be working, we only have 7.

Linux Linux Kernel
< 5.4.297, 5.10.241, 5.15.190, 6.1.147, 6.6.100, 6.12.40, 6.15.8, 6.16
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.3% (22th percentile)
NVD status
Modified
Published
2025-07-28
CVE-2025-38495 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-38495

Proof-of-concept code and exploit modules indexed by Sploitus