In the Linux kernel, the following vulnerability has been resolved:
can: peak_usb: fix shift-out-of-bounds issue
Explicitly uses a 64-bit constant when the number of bits used for its shifting is 32 (which is the case for PC CAN FD interfaces supported by this driver).
[mkl: update subject, apply manually]
[
{
"id": "CVE-2025-40020-2d6de080",
"target": {
"file": "drivers/net/can/usb/peak_usb/pcan_usb_core.c",
"function": "peak_usb_update_ts_now"
},
"digest": {
"length": 302.0,
"function_hash": "253991527747347985636916412076975703239"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@48822a59ecc47d353400d38b1941d3ae7591ffff",
"signature_version": "v1"
},
{
"id": "CVE-2025-40020-84363677",
"target": {
"file": "drivers/net/can/usb/peak_usb/pcan_usb_core.c",
"function": "peak_usb_update_ts_now"
},
"digest": {
"length": 302.0,
"function_hash": "253991527747347985636916412076975703239"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@572c656802781cc57f4a3231eefa83547e75ed78",
"signature_version": "v1"
},
{
"id": "CVE-2025-40020-89463baf",
"target": {
"file": "drivers/net/can/usb/peak_usb/pcan_usb_core.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"204462330077694532011379582298005256358",
"162661347171792116895930281378231080911",
"191502574067268151599819825960123078137",
"54346031029458763871811747910436079876"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@48822a59ecc47d353400d38b1941d3ae7591ffff",
"signature_version": "v1"
},
{
"id": "CVE-2025-40020-c1dbcadd",
"target": {
"file": "drivers/net/can/usb/peak_usb/pcan_usb_core.c",
"function": "peak_usb_update_ts_now"
},
"digest": {
"length": 302.0,
"function_hash": "253991527747347985636916412076975703239"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c443be70aaee42c2d1d251e0329e0a69dd96ae54",
"signature_version": "v1"
},
{
"id": "CVE-2025-40020-c6a75401",
"target": {
"file": "drivers/net/can/usb/peak_usb/pcan_usb_core.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"204462330077694532011379582298005256358",
"162661347171792116895930281378231080911",
"191502574067268151599819825960123078137",
"54346031029458763871811747910436079876"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@572c656802781cc57f4a3231eefa83547e75ed78",
"signature_version": "v1"
},
{
"id": "CVE-2025-40020-de182f16",
"target": {
"file": "drivers/net/can/usb/peak_usb/pcan_usb_core.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"204462330077694532011379582298005256358",
"162661347171792116895930281378231080911",
"191502574067268151599819825960123078137",
"54346031029458763871811747910436079876"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c443be70aaee42c2d1d251e0329e0a69dd96ae54",
"signature_version": "v1"
}
]