CVE-2025-21797 is a high-severity use-after-free vulnerability in the Linux kernel's Corsair Void HID driver, specifically affecting the linux_kernel product. This flaw, rated 7.8 CVSS, stems from a missed call to cancel_delayed_work_sync(), leading to potential memory corruption. An attacker with local privileges could exploit this with low complexity to achieve high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.13, < 6.13.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:* | ||
6.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.