CVE-2025-40020 — Incorrect Calculation in Linux
Severity
7.8HIGHOSV
OSV5.5OSV3.2
No vectorEPSS
0.1%
top 81.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
can: peak_usb: fix shift-out-of-bounds issue
Explicitly uses a 64-bit constant when the number of bits used for its
shifting is 32 (which is the case for PC CAN FD interfaces supported by
this driver).
[mkl: update subject, apply manually]
Affected Packages7 packages
▶CVEListV5linux/linuxbb4785551f64e18b2c8bb15a3bd2b22f5ebf624d — 572c656802781cc57f4a3231eefa83547e75ed78+8