Description
In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91: Fix possible out-of-boundary access at91_gpio_probe() doesn't check that given OF alias is not available or something went wrong when trying to get it. This might have consequences when accessing gpio_chips array with that value as an index. Note, that BUG() can be compiled out and hence won't actually perform the required checks.
Product status
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before 264a5cf0c422e65c94447a1ebebfac7c92690670
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before db5665cbfd766db7d8cd0e5fd6e3c0b412916774
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before 2ecafe59668d2506a68459a9d169ebe41a147a41
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before f1c1fdc41fbf7e308ced9c86f3f66345a3f6f478
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before eb435bc4c74acbb286cec773deac13d117d3ef39
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before e02e12d6a7ab76c83849a4122785650dc7edef65
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before 288c39286f759314ee8fb3a80a858179b4f306da
6732ae5cb47c4f9a72727585956f2a5e069d1637 (git) before 762ef7d1e6eefad9896560bfcb9bcf7f1b6df9c1
3.8
Any version before 3.8
5.4.295 (semver)
5.10.239 (semver)
5.15.186 (semver)
6.1.142 (semver)
6.6.94 (semver)
6.12.34 (semver)
6.15.3 (semver)
6.16 (original_commit_for_fix)
References
lists.debian.org/debian-lts-announce/2025/10/msg00008.html
lists.debian.org/debian-lts-announce/2025/10/msg00007.html
git.kernel.org/...c/264a5cf0c422e65c94447a1ebebfac7c92690670
git.kernel.org/...c/db5665cbfd766db7d8cd0e5fd6e3c0b412916774
git.kernel.org/...c/2ecafe59668d2506a68459a9d169ebe41a147a41
git.kernel.org/...c/f1c1fdc41fbf7e308ced9c86f3f66345a3f6f478
git.kernel.org/...c/eb435bc4c74acbb286cec773deac13d117d3ef39
git.kernel.org/...c/e02e12d6a7ab76c83849a4122785650dc7edef65
git.kernel.org/...c/288c39286f759314ee8fb3a80a858179b4f306da
git.kernel.org/...c/762ef7d1e6eefad9896560bfcb9bcf7f1b6df9c1