CVE-2025-38103 is an out-of-bounds read vulnerability in the Linux kernel's usbhid_parse() function, affecting Debian and other Linux distributions. It stems from improper parsing of HID descriptors, specifically the mandatory report descriptor. With a CVSS score of 7.1 (High), exploitation requires local access and could lead to high confidentiality and availability impacts. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.95, < 3.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.16.50, < 3.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.18.76, < 3.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.1.46, < 4.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.4.93, < 4.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
Jul 8, 2025kernel: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
Jul 3, 2025