SB2025090899 - Memory leak in Linux kernel comedi driver
Published: September 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-39686)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the insn_rw_emulate_bits() function in drivers/comedi/drivers.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7afba9221f70d4cbce0f417c558879cba0eb5e66
- https://git.kernel.org/stable/c/842f307a1d115b24f2bcb2415c4e344f11f55930
- https://git.kernel.org/stable/c/92352ed2f9ac422181e381c2430c2d0dfb46faa0
- https://git.kernel.org/stable/c/ab77e85bd3bc006ef40738f26f446a660813da44
- https://git.kernel.org/stable/c/ae8bc1f07bcb31b8636420e03d1f9c3df6219a2b
- https://git.kernel.org/stable/c/dc0a2f142d655700db43de90cb6abf141b73d908