CVE-2025-40020

Source
https://cve.org/CVERecord?id=CVE-2025-40020
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40020.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40020
Downstream
Related
Published
2025-10-24T12:24:56.311Z
Modified
2026-03-20T12:43:08.630617Z
Summary
can: peak_usb: fix shift-out-of-bounds issue
Details

In the Linux kernel, the following vulnerability has been resolved:

can: peak_usb: fix shift-out-of-bounds issue

Explicitly uses a 64-bit constant when the number of bits used for its shifting is 32 (which is the case for PC CAN FD interfaces supported by this driver).

[mkl: update subject, apply manually]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40020.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d
Fixed
572c656802781cc57f4a3231eefa83547e75ed78
Fixed
61b1dd4c614935169d12bdecc26906e37b508618
Fixed
48822a59ecc47d353400d38b1941d3ae7591ffff
Fixed
176c81cbf9c4e348610a421aad800087c0401f60
Fixed
17edec1830e48c0becd61642d0e40bc753243b16
Fixed
eb79ed970670344380e77d62f8188e8015648d94
Fixed
394c58017e5f41043584c345106cae16a4613710
Fixed
c443be70aaee42c2d1d251e0329e0a69dd96ae54

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40020.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4.0
Fixed
5.4.300
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.245
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.194
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.155
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.109
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.50
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40020.json"