In the Linux kernel, the following vulnerability has been resolved:
HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
The Chicony Electronics HP 5MP Cameras (USB ID 04F2:B824 & 04F2:B82C) report a HID sensor interface that is not actually implemented. Attempting to access this non-functional sensor via iio_info causes system hangs as runtime PM tries to wake up an unresponsive sensor.
Add these 2 devices to the HID ignore list since the sensor interface is non-functional by design and should not be exposed to userspace.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1b297ab6f38ca60a4ca7298b297944ec6043b2f4",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-2ec01bcb",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2b0931eee48208c25bb77486946dea8e96aa6a36",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-5865ddbc",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a2a91abd19c574b598b1c69ad76ad9c7eedaf062",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-a64dbba1",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@54bae4c17c11688339eb73a04fd24203bb6e7494",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-ba0a11a7",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c72536350e82b53a1be0f3bfdf1511bba2827102",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-c4cc40b2",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7ac00f019698f614a49cce34c198d0568ab0e1c2",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-cca85fa4",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3ce1d87d1f5d80322757aa917182deb7370963b9",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-dd76c1e0",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@35f1a5360ac68d9629abbb3930a0a07901cba296",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-e263a34d",
"signature_type": "Line",
"target": {
"file": "drivers/hid/hid-quirks.c"
}
}
]