PT-2025-49368 · Linux+2 · Linux Kernel+2

CVE-2025-40267

·

Published

2025-11-10

·

Updated

2026-02-24

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s io uring/rw functionality. A previous commit intended to improve cleanup processes inadvertently introduced a memory leak. Specifically, if internal caches overflow during a request, the allocated iovec may not be properly freed when the request is aborted early, leading to a potential memory leak. The issue is related to the recycling infrastructure and the handling of allocated iovecs during early failure scenarios.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08869
CVE-2025-40267
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu