In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Add missing delayed work cancel for headset status The cancel_delayed_work_sync() call was missed, causing a use-after-free in corsair_void_remove().
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025022610-CVE-2025-21797-04ee@gregkh/T