CVE-2025-21746 — Time-of-check Time-of-use (TOCTOU) Race Condition in Linux
Severity
4.7MEDIUMNVD
OSV5.5
EPSS
0.0%
top 97.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27
Latest updateSep 3
Description
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics - fix crash when enabling pass-through port
When enabling a pass-through port an interrupt might come before psmouse
driver binds to the pass-through port. However synaptics sub-driver
tries to access psmouse instance presumably associated with the
pass-through port to figure out if only 1 byte of response or entire
protocol packet needs to be forwarded to the pass-through port and may
crash if psmouse instanc…
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6
Affected Packages5 packages
▶CVEListV5linux/linux100e16959c3ca8cb7be788ed3e2c5867481f35f6 — a2cbcd70133dc0d4d4c95ad4cd5412b935354c7c+4