We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-38483

comedi: das16m1: Fix bit shift out of bounds



Description

In the Linux kernel, the following vulnerability has been resolved: comedi: das16m1: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: /* only irqs 2, 3, 4, 5, 6, 7, 10, 11, 12, 14, and 15 are valid */ if ((1 << it->options[1]) & 0xdcfc) { However, `it->options[i]` is an unchecked `int` value from userspace, so the shift amount could be negative or out of bounds. Fix the test by requiring `it->options[1]` to be within bounds before proceeding with the original test.

Reserved 2025-04-16 | Published 2025-07-28 | Updated 2025-07-28 | Assigner Linux

Product status

Default status
unaffected

729988507680b2ce934bce61d9ce0ea7b235914c before 65c03e6fc524eb2868abedffd8a4613d78abc288
affected

729988507680b2ce934bce61d9ce0ea7b235914c before adb7df8a8f9d788423e161b779764527dd3ec2d0
affected

729988507680b2ce934bce61d9ce0ea7b235914c before 076b13ee60eb01ed0d140ef261f95534562a3077
affected

729988507680b2ce934bce61d9ce0ea7b235914c before f211572818ed5bec2b3f5d4e0719ef8699b3c269
affected

729988507680b2ce934bce61d9ce0ea7b235914c before ed93c6f68a3be06e4e0c331c6e751f462dee3932
affected

Default status
affected

3.14
affected

Any version before 3.14
unaffected

6.1.147
unaffected

6.6.100
unaffected

6.12.40
unaffected

6.15.8
unaffected

6.16
unaffected

References

git.kernel.org/...c/65c03e6fc524eb2868abedffd8a4613d78abc288

git.kernel.org/...c/adb7df8a8f9d788423e161b779764527dd3ec2d0

git.kernel.org/...c/076b13ee60eb01ed0d140ef261f95534562a3077

git.kernel.org/...c/f211572818ed5bec2b3f5d4e0719ef8699b3c269

git.kernel.org/...c/ed93c6f68a3be06e4e0c331c6e751f462dee3932

cve.org (CVE-2025-38483)

nvd.nist.gov (CVE-2025-38483)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-38483

Support options

Helpdesk Chat, Email, Knowledgebase