cbcvebase.
CVE-2025-21923
published 2025-04-01

CVE-2025-21923: In the Linux kernel, the following vulnerability has been resolved: HID: hid-steam: Fix use-after-free when detaching device When a hid-steam device is removed…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
9.3th percentile
In the Linux kernel, the following vulnerability has been resolved: HID: hid-steam: Fix use-after-free when detaching device When a hid-steam device is removed it must clean up the client_hdev used for intercepting hidraw access. This can lead to scheduling deferred work to reattach the input device. Though the cleanup cancels the deferred work, this was done before the client_hdev itself is cleaned up, so it gets rescheduled. This patch fixes the ordering to make sure the deferred work is properly canceled.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.19-1 (forky)linux 6.12.19-1 (forky)
linuxlinux>= 053fa3888d2a957f4db26c05e503f4c6b9570a30 < ea3f18d2f02629653b7bfe42607737ccd1343e54ea3f18d2f02629653b7bfe42607737ccd1343e54
linuxlinux>= 3e38cbbfa0a128a9d64773240a9eb3bc7bae3b1a < a899adf7063c6745aaff1ec869f3c7f6329ed0a1a899adf7063c6745aaff1ec869f3c7f6329ed0a1
linuxlinux>= 6.12.16 < 6.12.196.12.19
linuxlinux>= 6.13.4 < 6.13.76.13.7
linuxlinux>= 6.6.79 < 6.6.836.6.83
linuxlinux>= 79504249d7e27cad4a3eeb9afc6386e418728ce0 < e53fc232a65f7488ab75d03a5b95f06aaada7262e53fc232a65f7488ab75d03a5b95f06aaada7262
linuxlinux>= e1147961b2145fa61c3078a4a797d9576cde91ab < 026714ec7546de741826324a6a1914c91024d06c026714ec7546de741826324a6a1914c91024d06c
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 6.12.16 < 6.12.196.12.19
linuxlinux_kernel>= 6.13.4 < 6.13.76.13.7
linuxlinux_kernel>= 6.6.79 < 6.6.836.6.83
msrcazl3_kernel_6.6.82.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.85.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.