CVE-2025-21992

Updated: 2026-01-05 01:33:35.562232

Description:

In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera The HP 5MP Camera (USB ID 0408:5473) reports a HID sensor interface that is not actually implemented. Attempting to access this non-functional sensor via iio_info causes system hangs as runtime PM tries to wake up an unresponsive sensor. [453] hid-sensor-hub 0003:0408:5473.0003: Report latency attributes: ffffffff:ffffffff [453] hid-sensor-hub 0003:0408:5473.0003: common attributes: 5:1, 2:1, 3:1 ffffffff:ffffffff Add this device to the HID ignore list since the sensor interface is non-functional by design and should not be exposed to userspace.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-11-05 04:53:14 This issue is a local-only availability flaw that triggers only when the HP 5MP USB camera with USB ...
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-11-05 04:53:16
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-11-05 04:53:13
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-11-05 04:53:15
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-11-05 04:53:15
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-11-05 04:53:12
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-11-05 04:53:11
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-11-05 04:53:13
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-11-05 04:53:12
Oracle Linux 7 ELS kernel-uek 5.4.17 5.5 MEDIUM Released CLSA-2025:1757963029 2025-09-16 11:21:09
Total: 16