CVE-2025-21746 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics - fix crash when enabling pass-through port When enabling a pass-through port an interrupt might come before psmouse driver binds to the pass-through port. However synaptics sub-driver tries to access psmouse instance presumably associated with the pass-through port to figure out if only 1 byte of response or entire protocol packet needs to be forwarded to the pass-through port and may crash if psmouse instance has not been attached to the port yet. Fix the crash by introducing open() and close() methods for the port and check if the port is open before trying to access psmouse instance. Because psmouse calls serio_open() only after attaching psmouse instance to serio port instance this prevents the potential crash.
A vulnerability in the Linux kernel's synaptics input driver can lead to a crash when enabling a pass-through port. This issue occurs because an interrupt may arrive before the psmouse driver has fully bound to the port. The synaptics sub-driver attempts to access the psmouse instance related to the port to determine whether to forward a single byte or an entire protocol packet. If the psmouse instance is not yet attached, this can result in a crash. The vulnerability affects several versions of the Linux kernel.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/08bd5b7c9a2401faabdaa1472d45c7de0755fd7e | kernel.org | Patch |
| https://git.kernel.org/stable/c/3e179d3f1ada963475395d81bfe91daef4d1a24c | kernel.org | Patch |
| https://git.kernel.org/stable/c/87da1ea93ec9f9f0004e5b12e78789bc94e360bf | kernel.org | Patch |
| https://git.kernel.org/stable/c/a2cbcd70133dc0d4d4c95ad4cd5412b935354c7c | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.5, < 6.6.80 >= 6.7, < 6.12.17 >= 6.13, < 6.13.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Apr 6, 2026 | Modified Analysis | [email protected] |
| Jan 30, 2026 | Modified Analysis | [email protected] |
| Oct 28, 2025 | Initial Analysis | [email protected] |
| Feb 27, 2025 | CVE Modified | kernel.org |
| Feb 27, 2025 | New CVE Received | kernel.org |