Impact
In the Linux kernel, the HID ASUS driver contains several critical weaknesses, including unchecked packet size processing in asus_raw_event, an unclean teardown routine that can hide failures in asus_probe, and a possible use–after–free when probe fails. Additionally, the driver performs sleeping calls within an atomic context and sends packets of incorrect size to the keyboard controller. These defects can lead to kernel memory corruption, unexpected crashes, or privilege escalation by an attacker able to inject malformed HID packets.
Affected Systems
The vulnerability affects all Linux distributions running a kernel before the fix that merged the two workqueues and added size checks to the HID ASUS driver. The affected component is the hid_asus module in the core kernel, which is deployed across a wide range of hardware that supports ASUS keyboard firmware. Any system that has not applied the patch commits 47669bec44fe12fe2c7adf2b299e980d7935a2ce or 744b3f930c1173ad57f49b614fc875d8d2715396 remains susceptible.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of exploitation in the wild. However, the lack of a public CVSS score means the exact impact severity is unclear. The likely attack vector requires local privilege access or the ability to direct HID packets to the affected driver, implying that remote exploitation is unlikely but a local attacker or compromised device could trigger the kernel buffer overrun or use–after–free, resulting in a kernel panic or escalation of privileges.
OpenCVE Enrichment