CVE-2025-21776
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-21776 is a vulnerability affecting the Linux kernel's USB hub driver. The issue arises due to a dereference error in the function usb_hub_adjust_deviceremovable(), which occurs when the driver binds to the wrong interface of a hub device that violates the USB specification by having more than one interface or configuration. This error can result in a general protection fault and potentially lead to system instability. To mitigate this issue, it's recommended to refuse hub devices that do not comply with the USB specification and limit the number of interfaces and configurations they support.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.