CVE-2025-38286

Source
https://cve.org/CVERecord?id=CVE-2025-38286
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38286.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38286
Downstream
Related
Published
2025-07-10T07:42:03.409Z
Modified
2026-05-07T04:17:38.095346Z
Summary
pinctrl: at91: Fix possible out-of-boundary access
Details

In the Linux kernel, the following vulnerability has been resolved:

pinctrl: at91: Fix possible out-of-boundary access

at91gpioprobe() doesn't check that given OF alias is not available or something went wrong when trying to get it. This might have consequences when accessing gpio_chips array with that value as an index. Note, that BUG() can be compiled out and hence won't actually perform the required checks.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38286.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6732ae5cb47c4f9a72727585956f2a5e069d1637
Fixed
264a5cf0c422e65c94447a1ebebfac7c92690670
Fixed
db5665cbfd766db7d8cd0e5fd6e3c0b412916774
Fixed
2ecafe59668d2506a68459a9d169ebe41a147a41
Fixed
f1c1fdc41fbf7e308ced9c86f3f66345a3f6f478
Fixed
eb435bc4c74acbb286cec773deac13d117d3ef39
Fixed
e02e12d6a7ab76c83849a4122785650dc7edef65
Fixed
288c39286f759314ee8fb3a80a858179b4f306da
Fixed
762ef7d1e6eefad9896560bfcb9bcf7f1b6df9c1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38286.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8.0
Fixed
5.4.295
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.239
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.186
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.142
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.94
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.34
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38286.json"