Executive brief
A vulnerability in the Linux kernel's ASUS HID driver could allow a malicious USB device to crash the system or potentially execute unauthorized code. By providing a specially crafted device descriptor, an attacker can trigger a memory error known as a 'use-after-free.' This occurs when the system attempts to access memory that has already been released, leading to instability or a full system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/hid/hid-asus.c within the Linux kernel. The flaw is triggered during the asus_probe process when hidinput_connect() is called. If a malicious HID device (such as a crafted ASUS ROG N-Key keyboard) provides a descriptor with undefined usage pages, the capability bitmaps may not be set. This causes hidinput_has_been_populated() to fail, leading to the premature freeing of the hid_input and underlying input device. Subsequent attempts to write to the freed input device name result in a UAF. The fix involves validating that HID_CLAIMED_INPUT is set before proceeding, ensuring the input device was successfully registered and not freed.
Affected products
- Linux Linux Kernel 6.13 to 6.16.5
Timeline
- 2025-08-10: other: Vulnerability fix authored
- 2025-09-16: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/5f3c0839b173f7f33415eb098331879e547d1d2d
- https://git.kernel.org/stable/c/7170122e2ae4ab378c9cdf7cc54dea8b0abbbca5
- https://git.kernel.org/stable/c/72a4ec018c9e9bc52f4f80eb3afb5d6a6b752275
- https://git.kernel.org/stable/c/9a9e4a8317437bf944fa017c66e1e23a0368b5c7
- https://git.kernel.org/stable/c/a8ca8fe7f516d27ece3afb995c3bd4d07dcbe62c
- https://git.kernel.org/stable/c/c0d77e3441a92d0b4958193c9ac1c3f81c6f1d1c
- https://git.kernel.org/stable/c/d3af6ca9a8c34bbd8cff32b469b84c9021c9e7e4