Linux Kernel Comedi DAS6402 Out-of-Bounds Bit Shift Vulnerability

Vulnerability

A vulnerability in the Linux kernel's Comedi driver for the DAS6402 interface allows for an out-of-bounds bit shift. This issue arises because the IRQ number is validated using a test that can be manipulated by unchecked integer values from userspace. The vulnerability could be exploited by providing an invalid IRQ option that disrupts normal operation.

Impact

Exploitation of this vulnerability could lead to undefined behavior in the kernel, potentially causing system instability or allowing for further exploitation.

Added: Jul 28, 2025, 12:55 PM
Updated: Jul 28, 2025, 12:55 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.