CVE-2025-38495

Published Jul 28, 2025

Last updated 5 months ago

Overview

Description
In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated buffer not account for that extra byte, meaning that instead of having 8 guaranteed bytes for implement to be working, we only have 7.
Source
416baaa9-dc9f-4396-8d5f-8c081fb06d67
NVD status
Analyzed
Products
linux_kernel, debian_linux

Risk scores

CVSS 3.1

Type
Primary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. Bam: USB HID info-leak exploit for CVE-2025-38494/CVE-2025-38495 Exploit ( https://t.co/YIpHkcD7Ky) by Andrey Konovalov ( https://t.co/XzbmO1Tfp0 ) for an integer underflow bug in the HID subsystem that allows leaking up to 64 KB of kernel memory over USB. The bug is still not

    @kaisarrmeoydw

    18 Jan 2026

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-38494/CVE-2025-38495 effects on first poweron <10sec

    @HI_Ricky

    9 Nov 2025

    1438 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Urgent: #SUSE releases kernel security patch for SLE 15 SP7. CVE-2025-38494 & CVE-2025-38495 (CVSS: 8.5) allow local privilege escalation via HID core flaws. Read more: 👉 https://t.co/hqvX8NENfc #Security https://t.co/IMBQt98VsH

    @Cezar_H_Linux

    24 Aug 2025

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. URGENT: #SUSE releases live patch for Linux Kernel on SLE 15 SP7. Patches 7 vulns incl. CVE-2025-38494 & CVE-2025-38495 (CVSS 8.5). HID, crypto, and net_sched flaws fixed. Read more: 👉 https://t.co/EntU9KIIJY #Security https://t.co/cnTMU9xEf8

    @Cezar_H_Linux

    24 Aug 2025

    71 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🔐 CRITICAL SECURITY UPDATE: #SUSE has released Live Patch 10 for SLE 15 SP6 to address four severe Linux kernel vulnerabilities (CVE-2025-38079, CVE-2025-38083, CVE-2025-38494, CVE-2025-38495). Read more:👉 https://t.co/5YM9f2Q65j #Security https://t.co/uOIWxyLxDi

    @Cezar_H_Linux

    22 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🔐 CRITICAL SECURITY UPDATE for @SUSE & @openSUSE users. Live Patch 59 for SLE 15 SP3 / Leap 15.3 patches 3 kernel vulnerabilities: CVE-2025-38494 (CVSS 8.5) CVE-2025-38495 (CVSS 8.5) CVE-2025-38079 (CVSS 7.3) Read more:👉 https://t.co/XSUmOav4

    @Cezar_H_Linux

    22 Aug 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CRITICAL: #SUSE releases Live Patch 55 for Linux Kernel (SLE 15 SP3/Leap 15.3). Patches 5 vulnerabilities, including CVE-2025-38494 & CVE-2025-38495 (CVSS 8.5). Local privilege escalation risk. Read more: 👉 https://t.co/r7wd7rkJZF #Security https://t.co/ObUKP5u6uk

    @Cezar_H_Linux

    22 Aug 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. URGENT: Patch your #SUSE Linux systems now! New kernel update fixes 5 critical vulnerabilities (CVSS up to 8.5): ✅ CVE-2025-38494. ✅ CVE-2025-38495. ✅ CVE-2025-38079. Affects: SLE 15 SP3, Leap 15.3. Read more:👉 https://t.co/fDkvsYuDOK #Security https://t.co/UUYWk2VlHp

    @Cezar_H_Linux

    22 Aug 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. URGENT: Patch #SUSE SLE 15 SP6 NOW. Live Patch 11 fixes 4 critical kernel vulnerabilities (CVE-2025-38494, CVE-2025-38495, CVE-2025-38079, CVE-2025-38083) with CVSS scores up to 8.5. Don't risk a breach. Read more:👉 https://t.co/Inku2xAAwA #Security https://t.co/hkVOvbNo6c

    @Cezar_H_Linux

    22 Aug 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. URGENT: #SUSE releases critical kernel security patch for SLE 15 SP6 / openSUSE Leap 15.6. Patches 4 vulnerabilities: ✅ CVE-2025-38494 (CVSS 8.5) ✅ CVE-2025-38495 (CVSS 8.5) ✅ CVE-2025-38079 ✅ CVE-2025-38083 Read more: 👉 https://t.co/anKbMUMkxS https://t.co/F367XNvS0u

    @Cezar_H_Linux

    21 Aug 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 URGENT: #SUSE Linux Kernel Patch Alert for SLE 15 SP4 / Leap 15.4. Patch 5 CVEs now, including two CRITICAL 8.5-rated flaws (CVE-2025-38494, CVE-2025-38495) in the HID core. Read more:👉 https://t.co/cv1fzx3R3v https://t.co/aMaQVtJQOl

    @Cezar_H_Linux

    20 Aug 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 URGENT: #SUSE Linux Kernel Live Patch 54 released. Patches 5 vulnerabilities: ⚠️ CVE-2025-38494 (CVSS: 8.5) ⚠️ CVE-2025-38495 (CVSS: 8.5) Impact: Privilege escalation, system compromise. Affects: #SLE15SP3, #openSUSE Leap 15.3. Read more:👉 https://t.co/BaLkjz2WsW

    @Cezar_H_Linux

    19 Aug 2025

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Critical kernel vulns fixed: CVE-2025-38494 & CVE-2025-38495 (CVSS 8.5). Risk: Local Privilege Escalation -> Full System Takeover. Impacts: SLE Live Patching/RT/Server/SAP (SP6/SP7). Read more: 👉 https://t.co/uyupdv4xfd #Security #SUSE https://t.co/UjzSS1dXn8

    @Cezar_H_Linux

    18 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2025-38495 In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report… https://t.co/tZ6ZdpHUrl

    @CVEnew

    28 Jul 2025

    213 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

  1. In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysfs and perf mode When trying to run perf and sysfs mode simultaneously, the WARN_ON() in tmc_etr_enable_hw() is triggered sometimes: WARNING: CPU: 42 PID: 3911571 at drivers/hwtracing/coresight/coresight-tmc-etr.c:1060 tmc_etr_enable_hw+0xc0/0xd8 [coresight_tmc] [..snip..] Call trace: tmc_etr_enable_hw+0xc0/0xd8 [coresight_tmc] (P) tmc_enable_etr_sink+0x11c/0x250 [coresight_tmc] (L) tmc_enable_etr_sink+0x11c/0x250 [coresight_tmc] coresight_enable_path+0x1c8/0x218 [coresight] coresight_enable_sysfs+0xa4/0x228 [coresight] enable_source_store+0x58/0xa8 [coresight] dev_attr_store+0x20/0x40 sysfs_kf_write+0x4c/0x68 kernfs_fop_write_iter+0x120/0x1b8 vfs_write+0x2c8/0x388 ksys_write+0x74/0x108 __arm64_sys_write+0x24/0x38 el0_svc_common.constprop.0+0x64/0x148 do_el0_svc+0x24/0x38 el0_svc+0x3c/0x130 el0t_64_sync_handler+0xc8/0xd0 el0t_64_sync+0x1ac/0x1b0 ---[ end trace 0000000000000000 ]--- Since the enablement of sysfs mode is separeted into two critical regions, one for sysfs buffer allocation and another for hardware enablement, it's possible to race with the perf mode. Fix this by double check whether the perf mode's been used before enabling the hardware in sysfs mode. mode: [sysfs mode] [perf mode] tmc_etr_get_sysfs_buffer() spin_lock(&drvdata->spinlock) [sysfs buffer allocation] spin_unlock(&drvdata->spinlock) spin_lock(&drvdata->spinlock) tmc_etr_enable_hw() drvdata->etr_buf = etr_perf->etr_buf spin_unlock(&drvdata->spinlock) spin_lock(&drvdata->spinlock) tmc_etr_enable_hw() WARN_ON(drvdata->etr_buf) // WARN sicne etr_buf initialized at the perf side spin_unlock(&drvdata->spinlock) With this fix, we retain the check for CS_MODE_PERF in get_etr_sysfs_buf. This ensures we verify whether the perf mode's already running before we actually allocate the buffer. Then we can save the time of allocating/freeing the sysfs buffer if race with the perf mode.CVE-2026-46272