SB2025090848 - Out-of-bounds read in Linux kernel comedi drivers driver
Published: September 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2025-39685)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the pcl726_attach() function in drivers/comedi/drivers/pcl726.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0eb4ed2aa261dee228f1668dbfa6d87353e8162d
- https://git.kernel.org/stable/c/5a33d07c94ba91306093e823112a7aa9727549f6
- https://git.kernel.org/stable/c/96cb948408b3adb69df7e451ba7da9d21f814d00
- https://git.kernel.org/stable/c/a3cfcd0c78c80ca7cd80372dc28f77d01be57bf6
- https://git.kernel.org/stable/c/bab220b0bb5af652007e278e8e8357f952b0e1ea
- https://git.kernel.org/stable/c/d8992c9a01f81128f36acb7c5755530e21fcd059