Junglewise Threat Intelligence

CVE-2025-39824: Linux Kernel use-after-free in ASUS HID driver

CVE-2025-39824 · Severity: high · CVSS 7.8 · Published 2025-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ASUS HID driver could allow a malicious USB device to crash the system or potentially execute unauthorized code. By providing a specially crafted device descriptor, an attacker can trigger a memory error known as a 'use-after-free.' This occurs when the system attempts to access memory that has already been released, leading to instability or a full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/hid/hid-asus.c within the Linux kernel. The flaw is triggered during the asus_probe process when hidinput_connect() is called. If a malicious HID device (such as a crafted ASUS ROG N-Key keyboard) provides a descriptor with undefined usage pages, the capability bitmaps may not be set. This causes hidinput_has_been_populated() to fail, leading to the premature freeing of the hid_input and underlying input device. Subsequent attempts to write to the freed input device name result in a UAF. The fix involves validating that HID_CLAIMED_INPUT is set before proceeding, ensuring the input device was successfully registered and not freed.

Affected products

  • Linux Linux Kernel 6.13 to 6.16.5

Timeline

  • 2025-08-10: other: Vulnerability fix authored
  • 2025-09-16: advisory: NVD publication date

References

Related threats