CVE-2025-37942

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-37942
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37942.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37942
Downstream
Published
2025-05-20T15:58:18.935Z
Modified
2025-11-28T02:35:10.327232Z
Summary
HID: pidff: Make sure to fetch pool before checking SIMULTANEOUS_MAX
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: pidff: Make sure to fetch pool before checking SIMULTANEOUS_MAX

As noted by Anssi some 20 years ago, pool report is sometimes messed up. This worked fine on many devices but casued oops on VRS DirectForce PRO.

Here, we're making sure pool report is refetched before trying to access any of it's fields. While loop was replaced with a for loop + exit conditions were moved aroud to decrease the possibility of creating an infinite loop scenario.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37942.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
211861869766a7bb7c72158aee0140ec67e182a7
Fixed
344d903be8b5c0733ed0f4bc5be34b4a26d905c8
Fixed
a6f5d30a5c7713238c5c65c98ad95dacb73688d5
Fixed
1f650dcec32d22deb1d6db12300a2b98483099a9

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.12.24
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.12
Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.14.3