SB2025072945 - Use of uninitialized resource in Linux kernel comedi driver
Published: July 29, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2025-38478)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the do_insnlist_ioctl() and do_insn_ioctl() functions in drivers/comedi/comedi_fops.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/46d8c744136ce2454aa4c35c138cc06817f92b8e
- https://git.kernel.org/stable/c/673ee92bd2d31055bca98a1d96b653f5284289c4
- https://git.kernel.org/stable/c/c42116dc70af6664526f7aa82cf937824ab42649
- https://git.kernel.org/stable/c/d3436638738ace8f101af7bdee2eae1bc38e9b29
- https://git.kernel.org/stable/c/fe8713fb4e4e82a4f91910d9a41bf0613e69a0b9