Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21992— HID: ignore non-functional sensor in HP 5MP Camera

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于HP 5MP Camera报告了一个未实际实现的HID传感器接口,可能导致系统挂起。

AI Predicted 5.3 Difficulty: Moderate EPSS 0.19% · P9

Possible ATT&CK Techniques 1 AI

T1059.001 · PowerShell

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux e04955db6a7c3fc4a1e6978649b61a6f5f8028e3< 7a7ada33879a631b05b536e66d1c5b1219d3bade affected
e04955db6a7c3fc4a1e6978649b61a6f5f8028e3< 6ca3d4d87af406a390a34ea924ab65c517e6e132 affected
e04955db6a7c3fc4a1e6978649b61a6f5f8028e3< 920ea73215dbf948b661b88a79cb47b7f96adfbd affected
e04955db6a7c3fc4a1e6978649b61a6f5f8028e3< 363236d709e75610b628c2a4337ccbe42e454b6d affected
6.3 affected
< 6.3 unaffected
6.6.84≤ 6.6.* unaffected
6.12.20≤ 6.12.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-21992

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HID: ignore non-functional sensor in HP 5MP Camera
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera The HP 5MP Camera (USB ID 0408:5473) reports a HID sensor interface that is not actually implemented. Attempting to access this non-functional sensor via iio_info causes system hangs as runtime PM tries to wake up an unresponsive sensor. [453] hid-sensor-hub 0003:0408:5473.0003: Report latency attributes: ffffffff:ffffffff [453] hid-sensor-hub 0003:0408:5473.0003: common attributes: 5:1, 2:1, 3:1 ffffffff:ffffffff Add this device to the HID ignore list since the sensor interface is non-functional by design and should not be exposed to userspace.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于HP 5MP Camera报告了一个未实际实现的HID传感器接口,可能导致系统挂起。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux e04955db6a7c3fc4a1e6978649b61a6f5f8028e3 ~ 7a7ada33879a631b05b536e66d1c5b1219d3bade -
Linux Linux 6.3 -

II. Public POCs for CVE-2025-21992

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21992

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-04-02 · 8 CVEs total

CVE-2025-21988 9.8 CRITICAL fs/netfs/read_collect: add to next->prev_donated
CVE-2025-21994 7.6 HIGH ksmbd: fix incorrect validation for num_aces field of smb_acl
CVE-2025-21993 iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
CVE-2025-21991 x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes
CVE-2025-21990 drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags
CVE-2025-21989 drm/amd/display: fix missing .is_two_pixels_per_container
CVE-2025-21987 drm/amdgpu: init return value in amdgpu_ttm_clear_buffer

IV. Related Vulnerabilities

V. Comments for CVE-2025-21992

No comments yet


Leave a comment