Cyber Resilience

CVE-2025-38494

Linux Kernel 3.15 – 5.4.297

Published
28 July 2025
Modified
30 July 2026
Patch / advisory
CVSS Score v3.1 7.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0020 10th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2025-38494 is a high-severity an unspecified weakness vulnerability in Linux Linux Kernel. Its CVSS base score is 7.8 (High).

Operationally, ranked at the 10th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed those…

more

checks and allowed invalid paramto be used.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-38108Same product: Debian Debian Linux
CVE-2025-39857Same product: Debian Debian Linux
CVE-2024-35936Same product: Debian Debian Linux
CVE-2025-38344Same product: Debian Debian Linux
CVE-2025-38203Same product: Debian Debian Linux
CVE-2024-26689Same product: Debian Debian Linux
CVE-2024-35905Same product: Debian Debian Linux
CVE-2023-52672Same product: Debian Debian Linux
CVE-2023-3609Same product: Debian Debian Linux
CVE-2025-37850Same product: Debian Debian Linux

Affected Assets

linux
linux kernel
6.16 · 3.15 — 5.4.297 · 5.5 — 5.10.241 · 5.11 — 5.15.190
debian
debian linux
11.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References