Out of bounds bit shift vulnerability in Linux kernel affecting multiple products
CVE-2025-38530
What is CVE-2025-38530?
A vulnerability has been identified in the Linux kernel concerning the comedi driver for the pcl812 product. The flaw arises from improper validation of an integer value sourced from userspace, potentially leading to out-of-bounds bit shifts. Specifically, the check for a supported IRQ number can result in negative or excessive shift amounts when unchecked inputs are processed. This oversight necessitates an amendment to the existing validation logic to ensure that ‘it->options[1]’ is confined to valid IRQ range values, explicitly establishing that only numbers from 1 to 15 are permissible for selecting interrupts, while the value zero indicates that interrupts should not be utilized.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux fcdb427bc7cf5e9e5d7280cf09c08dec49b49432 < 374d9b3eb4b08407997ef1fce96119d31e0c0bc4
Linux fcdb427bc7cf5e9e5d7280cf09c08dec49b49432 < 0489c30d080f07cc7f09d04de723d8c2ccdb61ef
Linux fcdb427bc7cf5e9e5d7280cf09c08dec49b49432 < 29ef03e5b84431171d6b77b822985b54bc44b793