PT-2025-23952 · Unknown+4 · Envoy Side-Cars+4

CVE-2025-40217

·

Publicado

2025-06-05

·

Atualizado

2026-08-30

CVSS v3.1

5.2

Média

VetorAV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) Envoy side-cars (affected versions not specified)
Description A flaw exists in the Linux kernel related to insufficient validation of extensible ioctls within the pidfs subsystem. This could potentially lead to issues with system stability or security. A critical buffer overflow was reported in Envoy side-cars, requiring immediate patching of Kubernetes clusters across multiple environments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2025-40217
ECHO-85AC-FB53-C7C8
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Produtos afetados

Debian
Envoy Side-Cars
Linuxmint
Linux Kernel
Ubuntu