{"id":"CVE-2025-38495","summary":"HID: core: ensure the allocated report buffer can contain the reserved report ID","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: ensure the allocated report buffer can contain the reserved report ID\n\nWhen the report ID is not used, the low level transport drivers expect\nthe first byte to be 0. However, currently the allocated buffer not\naccount for that extra byte, meaning that instead of having 8 guaranteed\nbytes for implement to be working, we only have 7.","modified":"2026-04-16T04:33:54.917283157Z","published":"2025-07-28T11:22:04.169Z","related":["SUSE-SU-2025:02820-1","SUSE-SU-2025:02821-1","SUSE-SU-2025:02823-1","SUSE-SU-2025:02827-1","SUSE-SU-2025:02830-1","SUSE-SU-2025:02832-1","SUSE-SU-2025:02833-1","SUSE-SU-2025:02834-1","SUSE-SU-2025:02846-1","SUSE-SU-2025:02848-1","SUSE-SU-2025:02849-1","SUSE-SU-2025:02850-1","SUSE-SU-2025:02851-1","SUSE-SU-2025:02852-1","SUSE-SU-2025:02853-1","SUSE-SU-2025:02854-1","SUSE-SU-2025:02857-1","SUSE-SU-2025:02858-1","SUSE-SU-2025:02859-1","SUSE-SU-2025:02860-1","SUSE-SU-2025:02871-1","SUSE-SU-2025:02873-1","SUSE-SU-2025:02875-1","SUSE-SU-2025:02876-1","SUSE-SU-2025:02878-1","SUSE-SU-2025:02883-1","SUSE-SU-2025:02884-1","SUSE-SU-2025:02894-1","SUSE-SU-2025:02897-1","SUSE-SU-2025:02902-1","SUSE-SU-2025:02908-1","SUSE-SU-2025:02909-1","SUSE-SU-2025:02911-1","SUSE-SU-2025:02917-1","SUSE-SU-2025:02918-1","SUSE-SU-2025:02922-1","SUSE-SU-2025:02923-1","SUSE-SU-2025:02926-1","SUSE-SU-2025:02930-1","SUSE-SU-2025:02932-1","SUSE-SU-2025:02933-1","SUSE-SU-2025:02934-1","SUSE-SU-2025:02936-1","SUSE-SU-2025:02937-1","SUSE-SU-2025:02938-1","SUSE-SU-2025:02942-1","SUSE-SU-2025:02943-1","SUSE-SU-2025:02944-1","SUSE-SU-2025:02945-1","SUSE-SU-2025:02955-1","SUSE-SU-2025:02969-1","SUSE-SU-2025:02996-1","SUSE-SU-2025:02997-1","SUSE-SU-2025:03011-1","SUSE-SU-2025:03023-1","SUSE-SU-2025:03344-1","SUSE-SU-2025:20577-1","SUSE-SU-2025:20586-1","SUSE-SU-2025:20601-1","SUSE-SU-2025:20602-1","SUSE-SU-2025:20633-1","SUSE-SU-2025:20634-1","SUSE-SU-2025:20635-1","SUSE-SU-2025:20636-1","SUSE-SU-2025:20637-1","SUSE-SU-2025:20638-1","SUSE-SU-2025:20639-1","SUSE-SU-2025:20640-1","SUSE-SU-2025:20641-1","SUSE-SU-2025:20642-1","SUSE-SU-2025:20643-1","SUSE-SU-2025:20644-1","SUSE-SU-2025:20645-1","SUSE-SU-2025:20646-1","SUSE-SU-2025:20647-1","SUSE-SU-2025:20648-1","SUSE-SU-2025:20676-1","SUSE-SU-2025:20677-1","SUSE-SU-2025:20678-1","SUSE-SU-2025:20679-1","SUSE-SU-2025:20680-1","SUSE-SU-2025:20681-1","SUSE-SU-2025:20682-1","SUSE-SU-2025:20684-1","SUSE-SU-2025:20685-1","SUSE-SU-2025:20686-1","SUSE-SU-2025:20687-1","SUSE-SU-2025:20688-1","SUSE-SU-2025:20689-1","SUSE-SU-2025:20690-1","SUSE-SU-2025:20713-1","SUSE-SU-2025:20781-1","SUSE-SU-2025:21074-1","SUSE-SU-2025:21139-1","SUSE-SU-2025:21179-1","SUSE-SU-2025:4123-1","openSUSE-SU-2025:20081-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38495.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/4f15ee98304b96e164ff2340e1dfd6181c3f42aa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7228e36c7875e4b035374cf68ca5e44dffa596b2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7fa83d0043370003e9a0b46ab7ae8f53b00fab06"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9f2892f7233a8f1320fe671d0f95f122191bfbcd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a262370f385e53ff7470efdcdaf40468e5756717"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a47d9d9895bad9ce0e840a39836f19ca0b2a343a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d3ed1d84a84538a39b3eb2055d6a97a936c108f2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fcda39a9c5b834346088c14b1374336b079466c1"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38495.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-38495"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4fa5a7f76cc7b6ac87f57741edd2b124851d119f"},{"fixed":"7228e36c7875e4b035374cf68ca5e44dffa596b2"},{"fixed":"9f2892f7233a8f1320fe671d0f95f122191bfbcd"},{"fixed":"7fa83d0043370003e9a0b46ab7ae8f53b00fab06"},{"fixed":"d3ed1d84a84538a39b3eb2055d6a97a936c108f2"},{"fixed":"fcda39a9c5b834346088c14b1374336b079466c1"},{"fixed":"a262370f385e53ff7470efdcdaf40468e5756717"},{"fixed":"a47d9d9895bad9ce0e840a39836f19ca0b2a343a"},{"fixed":"4f15ee98304b96e164ff2340e1dfd6181c3f42aa"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38495.json"}}],"schema_version":"1.7.5"}