CVE-2025-38556: HID: core: Harden s32ton() against conversion to 0 bits
Published Aug 19, 2025
·Updated
HID: core: Harden s32ton() against conversion to 0 bits
Affected Software
10 affected components
Linux Linux kernel
Microsoft azl3 kernel 6.6.104.2-4
Microsoft azl3 kernel 6.6.96.2-2
Microsoft azl3 kernel 6.6.112.1-2
Microsoft azl3 kernel 6.6.96.2-1
Microsoft cbl2 kernel 5.15.186.1-1
Linux Linux kernel>=2.6.20<6.12.46
Linux Linux kernel>=6.13<6.15.10
Linux Linux kernel>=6.16<6.16.1
Microsoft azl3 kernel 6.6.117.1-1
Event History
Aug 19, 2025
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·03:43 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·03:43 AM
Affected Software
Updated
via Microsoft·03:43 AM
SeverityAffected Software
Updated
via Microsoft·03:43 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-38556?
CVE-2025-38556 is classified as a high severity vulnerability due to its potential to cause system crashes.
2
How do I fix CVE-2025-38556?
To fix CVE-2025-38556, you need to update your Linux kernel to the latest patched version provided by your distribution.
3
Which versions of the Linux kernel are affected by CVE-2025-38556?
CVE-2025-38556 affects multiple versions of the Linux kernel prior to the fix being applied.
4
What are the potential impacts of CVE-2025-38556?
The potential impacts of CVE-2025-38556 include system instability and possible denial of service due to a shift-out-of-bounds exception.
5
Is CVE-2025-38556 a remote exploit?
CVE-2025-38556 is not considered a remote exploit, as it requires specific conditions within the system to trigger the vulnerability.