Bug 2356592 (CVE-2025-21928) - CVE-2025-21928 kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
Summary: CVE-2025-21928 kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_...
Keywords:
Status: NEW
Alias: CVE-2025-21928
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-04-01 16:01 UTC by OSIDB Bzimport
Modified: 2025-10-16 08:10 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:12662 0 None None None 2025-08-04 09:20:45 UTC
Red Hat Product Errata RHSA-2025:12746 0 None None None 2025-08-04 16:18:28 UTC
Red Hat Product Errata RHSA-2025:12752 0 None None None 2025-08-04 16:51:26 UTC
Red Hat Product Errata RHSA-2025:12753 0 None None None 2025-08-04 16:23:28 UTC
Red Hat Product Errata RHSA-2025:13029 0 None None None 2025-08-05 15:48:27 UTC
Red Hat Product Errata RHSA-2025:13030 0 None None None 2025-08-05 15:55:27 UTC
Red Hat Product Errata RHSA-2025:13061 0 None None None 2025-08-05 17:57:17 UTC
Red Hat Product Errata RHSA-2025:13120 0 None None None 2025-08-06 05:16:13 UTC
Red Hat Product Errata RHSA-2025:13135 0 None None None 2025-08-06 07:51:29 UTC
Red Hat Product Errata RHSA-2025:13633 0 None None None 2025-08-11 14:17:51 UTC
Red Hat Product Errata RHSA-2025:13776 0 None None None 2025-08-13 02:41:29 UTC
Red Hat Product Errata RHSA-2025:13781 0 None None None 2025-08-13 09:36:27 UTC
Red Hat Product Errata RHSA-2025:14136 0 None None None 2025-08-20 08:08:30 UTC
Red Hat Product Errata RHSA-2025:14746 0 None None None 2025-08-27 11:40:44 UTC
Red Hat Product Errata RHSA-2025:14748 0 None None None 2025-08-27 12:39:46 UTC

Description OSIDB Bzimport 2025-04-01 16:01:30 UTC
In the Linux kernel, the following vulnerability has been resolved:

HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()

The system can experience a random crash a few minutes after the driver is
removed. This issue occurs due to improper handling of memory freeing in
the ishtp_hid_remove() function.

The function currently frees the `driver_data` directly within the loop
that destroys the HID devices, which can lead to accessing freed memory.
Specifically, `hid_destroy_device()` uses `driver_data` when it calls
`hid_ishtp_set_feature()` to power off the sensor, so freeing
`driver_data` beforehand can result in accessing invalid memory.

This patch resolves the issue by storing the `driver_data` in a temporary
variable before calling `hid_destroy_device()`, and then freeing the
`driver_data` after the device is destroyed.

Comment 6 errata-xmlrpc 2025-08-04 09:20:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:12662 https://access.redhat.com/errata/RHSA-2025:12662

Comment 7 errata-xmlrpc 2025-08-04 16:18:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:12746 https://access.redhat.com/errata/RHSA-2025:12746

Comment 8 errata-xmlrpc 2025-08-04 16:23:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:12753 https://access.redhat.com/errata/RHSA-2025:12753

Comment 9 errata-xmlrpc 2025-08-04 16:51:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:12752 https://access.redhat.com/errata/RHSA-2025:12752

Comment 10 errata-xmlrpc 2025-08-05 15:48:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:13029 https://access.redhat.com/errata/RHSA-2025:13029

Comment 11 errata-xmlrpc 2025-08-05 15:55:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:13030 https://access.redhat.com/errata/RHSA-2025:13030

Comment 12 errata-xmlrpc 2025-08-05 17:57:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:13061 https://access.redhat.com/errata/RHSA-2025:13061

Comment 13 errata-xmlrpc 2025-08-06 05:16:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2025:13120 https://access.redhat.com/errata/RHSA-2025:13120

Comment 14 errata-xmlrpc 2025-08-06 07:51:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:13135 https://access.redhat.com/errata/RHSA-2025:13135

Comment 16 errata-xmlrpc 2025-08-11 14:17:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:13633 https://access.redhat.com/errata/RHSA-2025:13633

Comment 17 errata-xmlrpc 2025-08-13 02:41:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:13776 https://access.redhat.com/errata/RHSA-2025:13776

Comment 18 errata-xmlrpc 2025-08-13 09:36:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:13781 https://access.redhat.com/errata/RHSA-2025:13781

Comment 19 errata-xmlrpc 2025-08-20 08:08:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:14136 https://access.redhat.com/errata/RHSA-2025:14136

Comment 20 errata-xmlrpc 2025-08-27 11:40:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:14746 https://access.redhat.com/errata/RHSA-2025:14746

Comment 21 errata-xmlrpc 2025-08-27 12:39:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:14748 https://access.redhat.com/errata/RHSA-2025:14748


Note You need to log in before you can comment on or make changes to this bug.