U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-21992

Change History

New CVE Received from kernel.org 4/02/2025 9:15:43 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

HID: ignore non-functional sensor in HP 5MP Camera

The HP 5MP Camera (USB ID 0408:5473) reports a HID sensor interface that
is not actually implemented. Attempting to access this non-functional
sensor via iio_info causes system hangs as runtime PM tries to wake up
an unresponsive sensor.

  [453] hid-sensor-hub 0003:0408:5473.0003: Report latency attributes: ffffffff:ffffffff
  [453] hid-sensor-hub 0003:0408:5473.0003: common attributes: 5:1, 2:1, 3:1 ffffffff:ffffffff

Add this device to the HID ignore list since the sensor interface is
non-functional by design and should not be exposed to userspace.
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/363236d709e75610b628c2a4337ccbe42e454b6d
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/6ca3d4d87af406a390a34ea924ab65c517e6e132
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/7a7ada33879a631b05b536e66d1c5b1219d3bade
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/920ea73215dbf948b661b88a79cb47b7f96adfbd
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/9acdb0059fb6b82158e15adae91e629cb5974564