Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38103

19
FAUCET Score

CVE-2025-38103 is an out-of-bounds read vulnerability in the Linux kernel's usbhid_parse() function, affecting Debian and other Linux distributions. It stems from improper parsing of HID descriptors, specifically the mandatory report descriptor. With a CVSS score of 7.1 (High), exploitation requires local access and could lead to high confidentiality and availability impacts. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.2.95, < 3.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.16.50, < 3.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.18.76, < 3.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.1.46, < 4.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.4.93, < 4.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 31st percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.92.2-2 on Azure Linux 3.0Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: 19880-17084Fixed in: 6.6.96.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
grafanavendor investigatingvia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel

Vendor Advisories (8)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
microsoft2025-Jul/CVE-2025-38103Moderate

HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()

Jul 8, 2025
redhatCVE-2025-38103Moderate

kernel: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()

Jul 3, 2025

References

git.kernel.org / stable/c/1df80d748f984290c895e843401824215dcfbfb0
Patch
git.kernel.org / stable/c/41827a2dbdd7880df9881506dee13bc88d4230bb
Patch
git.kernel.org / stable/c/485e1b741eb838cbe1d6b0e81e5ab62ae6c095cf
Patch
git.kernel.org / stable/c/4fa7831cf0ac71a0a345369d1a6084f2b096e55e
Patch
git.kernel.org / stable/c/74388368927e9c52a69524af5bbd6c55eb4690de
Patch
git.kernel.org / stable/c/7a6d6b68db128da2078ccd9a751dfa3f75c9cf5b
Patch
git.kernel.org / stable/c/a8f842534807985d3a676006d140541b87044345
Patch
git.kernel.org / stable/c/fe7f7ac8e0c708446ff017453add769ffc15deed
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory