Executive brief
A vulnerability was identified in the Linux kernel's Comedi driver for PCL-726 data acquisition boards. A local user could provide an excessively large interrupt request (IRQ) number, leading to an out-of-bounds memory access. This could result in a system crash (denial of service) or potentially allow the exposure of sensitive kernel memory.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the pcl726_attach function within drivers/comedi/drivers/pcl726.c. The driver fails to validate the IRQ number passed via it->options[1] before using it in a bitwise shift operation (1 << it->options[1]) to check against the board's IRQ mask. Providing a large value (e.g., 0x80008000) or a value of 31 triggers undefined behavior or out-of-bounds access. The fix introduces a bounds check (it->options[1] < 16) and uses unsigned integer constants (1U) to prevent signed integer overflow and invalid memory access. This is reachable by local users with permissions to configure Comedi devices.
Affected products
- Linux Linux Kernel 3.13 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-09-05: disclosed
- 2025-09-05: advisory
- 2025-08-28: patched
References
- https://git.kernel.org/stable/c/0eb4ed2aa261dee228f1668dbfa6d87353e8162d
- https://git.kernel.org/stable/c/5a33d07c94ba91306093e823112a7aa9727549f6
- https://git.kernel.org/stable/c/96cb948408b3adb69df7e451ba7da9d21f814d00
- https://git.kernel.org/stable/c/a3cfcd0c78c80ca7cd80372dc28f77d01be57bf6
- https://git.kernel.org/stable/c/bab220b0bb5af652007e278e8e8357f952b0e1ea
- https://git.kernel.org/stable/c/d8992c9a01f81128f36acb7c5755530e21fcd059
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html