In the Linux kernel, the following vulnerability has been resolved:
HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
The Chicony Electronics HP 5MP Cameras (USB ID 04F2:B824 & 04F2:B82C) report a HID sensor interface that is not actually implemented. Attempting to access this non-functional sensor via iio_info causes system hangs as runtime PM tries to wake up an unresponsive sensor.
Add these 2 devices to the HID ignore list since the sensor interface is non-functional by design and should not be exposed to userspace.
[
{
"target": {
"file": "drivers/hid/hid-quirks.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a2a91abd19c574b598b1c69ad76ad9c7eedaf062",
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-a64dbba1"
},
{
"target": {
"file": "drivers/hid/hid-quirks.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7ac00f019698f614a49cce34c198d0568ab0e1c2",
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-cca85fa4"
},
{
"target": {
"file": "drivers/hid/hid-quirks.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"180107182596556088249085953308567338459",
"299428932222239291323422855864316296205",
"308182955120446303214537612918305011769",
"2063829520204414406754136349670458604"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@35f1a5360ac68d9629abbb3930a0a07901cba296",
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38540-e263a34d"
}
]