CVE-2025-38529: comedi: aio_iiro_16: Fix bit shift out of bounds
Published Aug 16, 2025
·Updated
comedi: aioiiro16: Fix bit shift out of bounds
Affected Software
18 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=4.0<5.4.297
Linux Linux kernel>=5.5<5.10.241
Linux Linux kernel>=5.11<5.15.190
Linux Linux kernel>=5.16<6.1.147
Linux Linux kernel>=6.2<6.6.100
Linux Linux kernel>=6.7<6.12.40
Linux Linux kernel>=6.13<6.15.8
Linux Linux kernel=6.16-rc1
Linux Linux kernel=6.16-rc2
Linux Linux kernel=6.16-rc3
Linux Linux kernel=6.16-rc4
Linux Linux kernel=6.16-rc5
Linux Linux kernel=6.16-rc6
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.96.2-2
Microsoft cbl2 kernel 5.15.186.1-1
Microsoft azl3 kernel 6.6.96.2-1
Remediation
Event History
Aug 16, 2025
CVE Published
via MITRE·11:12 AM
Data Sourced
via MITRE·11:12 AM
Description
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·01:42 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:42 AM
DescriptionSeverity
Updated
via Microsoft·08:42 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38529?
CVE-2025-38529 has a medium severity rating due to potential security risks associated with unchecked integer values.
2
How do I fix CVE-2025-38529?
To fix CVE-2025-38529, update your Linux kernel to the latest stable version where the vulnerability has been resolved.
3
What software is affected by CVE-2025-38529?
CVE-2025-38529 affects the Linux kernel specifically in the comedi driver regarding IRQ number validation.
4
What are the risks of CVE-2025-38529 if left unpatched?
If left unpatched, CVE-2025-38529 could lead to system instability or exploitation through unchecked integer value manipulations.
5
When was CVE-2025-38529 disclosed?
CVE-2025-38529 was disclosed in a recent Linux kernel update addressing multiple vulnerabilities.