5.5

CVE-2025-39808

HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()

In the Linux kernel, the following vulnerability has been resolved:

HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()

in ntrig_report_version(), hdev parameter passed from hid_probe().
sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null
if hdev->dev.parent->parent is null, usb_dev has
invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned
when usb_rcvctrlpipe() use usb_dev,it trigger
page fault error for address(0xffffffffffffff58)

add null check logic to ntrig_report_version()
before calling hid_to_usb_dev()
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.37 < 5.4.298
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.242
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.191
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.150
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.104
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.45
Linux ≫ Linux Kernel Version >= 6.13 < 6.16.5
Linux ≫ Linux Kernel Version 6.17 Update rc1
Linux ≫ Linux Kernel Version 6.17 Update rc2
Linux ≫ Linux Kernel Version 6.17 Update rc3
Debian ≫ Debian Linux Version 11.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/22ddb5eca4af5e69dffe2b54551d2487424448f1
Patch
https://git.kernel.org/stable/c/019c34ca11372de891c06644846eb41fca7c890c
Patch
https://git.kernel.org/stable/c/4338b0f6544c3ff042bfbaf40bc9afe531fb08c7
Patch
https://git.kernel.org/stable/c/6070123d5344d0950f10ef6a5fdc3f076abb7ad2
Patch
https://git.kernel.org/stable/c/e422370e6ab28478872b914cee5d49a9bdfae0c6
Patch
https://git.kernel.org/stable/c/98520a9a3d69a530dd1ee280cbe0abc232a35bff
Patch
https://git.kernel.org/stable/c/183def8e4d786e50165e5d992df6a3083e45e16c
Patch
https://git.kernel.org/stable/c/185c926283da67a72df20a63a5046b3b4631b7d9
Patch
https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
Third Party Advisory
https://cert-portal.siemens.com/productcert/html/ssa-032379.html