CVE-2025-38654

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38654
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38654.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38654
Downstream
Published
2025-08-22T16:00:58.153Z
Modified
2025-11-27T02:32:12.279113Z
Summary
pinctrl: canaan: k230: Fix order of DT parse and pinctrl register
Details

In the Linux kernel, the following vulnerability has been resolved:

pinctrl: canaan: k230: Fix order of DT parse and pinctrl register

Move DT parse before pinctrl register. This ensures that device tree parsing is done before calling devmpinctrlregister() to prevent using uninitialized pin resources.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2025/38xxx/CVE-2025-38654.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
545887eab6f6776a7477fe7e83860eab57138b03
Fixed
02c1deb1bff2b6d242e29a51e56107495979a2b8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
545887eab6f6776a7477fe7e83860eab57138b03
Fixed
0ec03251d01494ef207089b5bd626becfd05fd86
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
545887eab6f6776a7477fe7e83860eab57138b03
Fixed
d94a32ac688f953dc9a9f12b5b4139ecad841bbb

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.10
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.1