CVE-2025-39684

comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl()

References

Notes

 carnil> Introduced in ed9eccbe8970 ("Staging: add comedi core"). Vulnerable versions:
 carnil> 2.6.29.

Bugs

Status

Branch Status
upstream released (6.17-rc3) [3cd212e895ca2d58963fdc6422502b10dd3966bb]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.16-upstream-stable released (6.16.4) [aecf0d557ddd95ce68193a5ee1dc4c87415ff08a]
6.12-upstream-stable released (6.12.44) [f3b0c9ec54736f3b8118f93a473d22e11ee65743]
6.6-upstream-stable released (6.6.103) [d84f6e77ebe3359394df32ecd97e0d76a25283dc]
6.1-upstream-stable released (6.1.149) [ff4a7c18799c7fe999fa56c5cf276e13866b8c1a]
5.10-upstream-stable needed
sid released (6.16.5-1)
6.12-trixie-security released (6.12.48-1)
6.1-bookworm-security released (6.1.153-1)
5.10-bullseye-security needed