CVE-2025-38495: HID: core: ensure the allocated report buffer can contain the reserved report ID
Published Jul 28, 2025
·Updated
HID: core: ensure the allocated report buffer can contain the reserved report ID
Affected Software
18 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=3.15<5.4.297
Linux Linux kernel>=5.5<5.10.241
Linux Linux kernel>=5.11<5.15.190
Linux Linux kernel>=5.16<6.1.147
Linux Linux kernel>=6.2<6.6.100
Linux Linux kernel>=6.7<6.12.40
Linux Linux kernel>=6.13<6.15.8
Linux Linux kernel=6.16-rc1
Linux Linux kernel=6.16-rc2
Linux Linux kernel=6.16-rc3
Linux Linux kernel=6.16-rc4
Linux Linux kernel=6.16-rc5
Linux Linux kernel=6.16-rc6
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2
Microsoft cbl2 kernel 5.15.186.1-1
Event History
Jul 28, 2025
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
DescriptionSeverity
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·01:14 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:14 AM
SeverityAffected Software
Updated
via Microsoft·08:14 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-38495?
CVE-2025-38495 has been classified with a moderate severity level due to its potential impact on the Linux kernel's HID subsystem.
2
How do I fix CVE-2025-38495?
To fix CVE-2025-38495, users should update to the latest version of the Linux kernel where the vulnerability has been patched.
3
What systems are affected by CVE-2025-38495?
CVE-2025-38495 affects systems running the vulnerable versions of the Linux kernel that involve HID transport drivers.
4
Who is responsible for addressing CVE-2025-38495?
The Linux kernel maintainers are responsible for addressing CVE-2025-38495 through timely updates and patches.
5
What are the potential consequences of CVE-2025-38495?
The potential consequences of CVE-2025-38495 include improper handling of HID report data, which could lead to unexpected behavior in devices relying on the kernel.