cbcvebase.
CVE-2025-21928
published 2025-04-01

CVE-2025-21928: In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() The system can…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() The system can experience a random crash a few minutes after the driver is removed. This issue occurs due to improper handling of memory freeing in the ishtp_hid_remove() function. The function currently frees the `driver_data` directly within the loop that destroys the HID devices, which can lead to accessing freed memory. Specifically, `hid_destroy_device()` uses `driver_data` when it calls `hid_ishtp_set_feature()` to power off the sensor, so freeing `driver_data` beforehand can result in accessing invalid memory. This patch resolves the issue by storing the `driver_data` in a temporary variable before calling `hid_destroy_device()`, and then freeing the `driver_data` after the device is destroyed.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < 0c1fb475ef999d6c22fc3f963fdf20cb3ed1b03d0c1fb475ef999d6c22fc3f963fdf20cb3ed1b03d
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < d3faae7f42181865c799d88c5054176f38ae4625d3faae7f42181865c799d88c5054176f38ae4625
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < 01b18a330cda61cc21423a7d1af92cf31ded8f6001b18a330cda61cc21423a7d1af92cf31ded8f60
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < cf1a6015d2f6b1f0afaa0fd6a0124ff2c7943394cf1a6015d2f6b1f0afaa0fd6a0124ff2c7943394
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < 560f4d1299342504a6ab8a47f575b5e6b8345ada560f4d1299342504a6ab8a47f575b5e6b8345ada
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < dea6a349bcaf243fff95dfd0428a26be6a0fb44edea6a349bcaf243fff95dfd0428a26be6a0fb44e
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < eb0695d87a81e7c1f0509b7d8ee7c65fbc26aec9eb0695d87a81e7c1f0509b7d8ee7c65fbc26aec9
linuxlinux>= 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 < 07583a0010696a17fb0942e0b499a62785c5fc9f07583a0010696a17fb0942e0b499a62785c5fc9f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 4.9 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1316.1.131
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.