PT-2025-42777 · Linux+3 · Linux Kernel+3

CVE-2025-40008

·

Publicado

2025-09-11

·

Atualizado

2026-08-30

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc3
Description A flaw exists in the Linux kernel related to out-of-bounds access to shadow memory within the Kernel Memory Sanitizer (KMSAN). Specifically, when running sha224 kunit on a KMSAN-enabled kernel, a crash occurs in kmsan internal set shadow origin(). This is triggered when memset() is called on a buffer that is not 4-byte aligned and extends to the end of a guard page. The root cause is an incorrect calculation of shadow memory addresses within the kmsan internal set shadow origin() function, leading to reads from unmapped shadow memory. The function kmsan internal set shadow origin() is involved in the process.
Recommendations Update to a version of the Linux kernel greater than or equal to 6.17.0-rc3.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-13574
CVE-2025-40008
DLA-4379-1
DSA-6053-1
ECHO-FC08-79C1-3E6B
MGASA-2025-0309
MGASA-2025-0310
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Produtos afetados

Debian
Linuxmint
Linux Kernel
Ubuntu