Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21928— HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()

AI Predicted 4.9 Difficulty: Theoretical EPSS 0.20% · P10

Possible ATT&CK Techniques 1AI

T1003 · OS Credential Dumping

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< 0c1fb475ef999d6c22fc3f963fdf20cb3ed1b03daffected
0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< d3faae7f42181865c799d88c5054176f38ae4625affected
0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< 01b18a330cda61cc21423a7d1af92cf31ded8f60affected
0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< cf1a6015d2f6b1f0afaa0fd6a0124ff2c7943394affected
0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< 560f4d1299342504a6ab8a47f575b5e6b8345adaaffected
0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< dea6a349bcaf243fff95dfd0428a26be6a0fb44eaffected
0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< eb0695d87a81e7c1f0509b7d8ee7c65fbc26aec9affected
0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6< 07583a0010696a17fb0942e0b499a62785c5fc9faffected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-21928

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() The system can experience a random crash a few minutes after the driver is removed. This issue occurs due to improper handling of memory freeing in the ishtp_hid_remove() function. The function currently frees the `driver_data` directly within the loop that destroys the HID devices, which can lead to accessing freed memory. Specifically, `hid_destroy_device()` uses `driver_data` when it calls `hid_ishtp_set_feature()` to power off the sensor, so freeing `driver_data` beforehand can result in accessing invalid memory. This patch resolves the issue by storing the `driver_data` in a temporary variable before calling `hid_destroy_device()`, and then freeing the `driver_data` after the device is destroyed.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ishtp_hid_remove存在UAF。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 0b28cb4bcb17dcb5fe0763fc3e1a94398b8f6cf6 ~ 0c1fb475ef999d6c22fc3f963fdf20cb3ed1b03d -
LinuxLinux 4.9 -

II. Public POCs for CVE-2025-21928

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21928

登录查看更多情报信息。

Patches & Fixes for CVE-2025-21928 (2)

Same Patch Batch · Linux · 2025-04-01 · 93 CVEs total

CVE-2025-219478.1 HIGHksmbd: fix type confusion via race condition when using ipc_msg_send_request
CVE-2025-21925llc: do not use skb_get() before dev_queue_xmit()
CVE-2025-21932mm: abort vma_modify() on merge out of memory failure
CVE-2025-21935rapidio: add check for rio_add_net() in rio_scan_alloc_net()
CVE-2025-21937Bluetooth: Add check for mgmt_alloc_skb() in mgmt_remote_name()
CVE-2025-21936Bluetooth: Add check for mgmt_alloc_skb() in mgmt_device_connected()
CVE-2025-21939drm/xe/hmm: Don't dereference struct page pointers without notifier lock
CVE-2025-21938mptcp: fix 'scheduling while atomic' in mptcp_pm_nl_append_new_local_addr
CVE-2025-21934rapidio: fix an API misues when rio_add_net() fails
CVE-2025-21927nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
CVE-2025-21926net: gso: fix ownership in __udp_gso_segment
CVE-2025-21929HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove()
CVE-2025-21924net: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns an e
CVE-2025-21922ppp: Fix KMSAN uninit-value warning with bpf
CVE-2025-21923HID: hid-steam: Fix use-after-free when detaching device
CVE-2025-21920vlan: enforce underlying device type
CVE-2025-21921net: ethtool: netlink: Allow NULL nlattrs when getting a phy_device
CVE-2025-21919sched/fair: Fix potential memory corruption in child_cfs_rq_on_list
CVE-2025-21918usb: typec: ucsi: Fix NULL pointer access
CVE-2025-21917usb: renesas_usbhs: Flush the notify_hotplug_work

Showing top 20 of 93 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-21928

No comments yet


Leave a comment