cbcvebase.
CVE-2025-40020
published 2025-10-24

CVE-2025-40020: In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix shift-out-of-bounds issue Explicitly uses a 64-bit constant when the…

PriorityP421high7.8
EPSS
0.20%
9.7th percentile
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix shift-out-of-bounds issue Explicitly uses a 64-bit constant when the number of bits used for its shifting is 32 (which is the case for PC CAN FD interfaces supported by this driver). [mkl: update subject, apply manually]

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < 572c656802781cc57f4a3231eefa83547e75ed78572c656802781cc57f4a3231eefa83547e75ed78
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < 61b1dd4c614935169d12bdecc26906e37b50861861b1dd4c614935169d12bdecc26906e37b508618
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < 48822a59ecc47d353400d38b1941d3ae7591ffff48822a59ecc47d353400d38b1941d3ae7591ffff
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < 176c81cbf9c4e348610a421aad800087c0401f60176c81cbf9c4e348610a421aad800087c0401f60
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < 17edec1830e48c0becd61642d0e40bc753243b1617edec1830e48c0becd61642d0e40bc753243b16
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < eb79ed970670344380e77d62f8188e8015648d94eb79ed970670344380e77d62f8188e8015648d94
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < 394c58017e5f41043584c345106cae16a4613710394c58017e5f41043584c345106cae16a4613710
linuxlinux>= bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d < c443be70aaee42c2d1d251e0329e0a69dd96ae54c443be70aaee42c2d1d251e0329e0a69dd96ae54
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 3.4.0 < 5.4.3005.4.300
linuxlinux_kernel>= 5.11.0 < 5.15.1945.15.194
linuxlinux_kernel>= 5.16.0 < 6.1.1556.1.155
linuxlinux_kernel>= 5.5.0 < 5.10.2455.10.245
linuxlinux_kernel>= 6.13.0 < 6.16.106.16.10
linuxlinux_kernel>= 6.2.0 < 6.6.1096.6.109
linuxlinux_kernel>= 6.7.0 < 6.12.506.12.50
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.