CVE-2025-38224 | Linux Kernel prior 6.12.35/6.15.4/6.16-rc1 can alloc_candev array index (EUVD-2025-20032 / Nessus ID 243387)
A vulnerability was found in Linux Kernel up to 6.12.34/6.15.3/f14512f3ee09cda986191c8dd7f54972afa2c763. It has been declared as problematic. The affected element is the function alloc_candev of the component can. Such manipulation leads to improper validation of array index.
This vulnerability is documented as CVE-2025-38224. The attack requires being on the local network. There is not any exploit available.
It is recommended to upgrade the affected component.