CVE-2025-21797

HIGH

Linux Kernel 6.13-6.13.3 - Use-After-Free in HID Corsair Void Headset Status

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Add missing delayed work cancel for headset status The cancel_delayed_work_sync() call was missed, causing a use-after-free in corsair_void_remove().

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 10.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (9)
linux/Kernel 6.13.0 - 6.13.4linux
Linux/Linux < 6.13
Linux/Linux 6.13
Linux/Linux 6.13.4 - 6.13.*
Linux/Linux 6.14
Linux/Linux 6ea2a6fd3872e60a4d500b548ad65ed94e459ddd - 2dcb56a0a4da6946f6c18288da595c13e0d2af86
Linux/Linux 6ea2a6fd3872e60a4d500b548ad65ed94e459ddd - 48e487b002891eb0aeaec704c9bed51f028deff1
linux/linux_kernel 6.14 rc1 (2 CPE variants)
linux/linux_kernel 6.13 - 6.13.4
Published Feb 27, 2025
Tracked Since Feb 18, 2026