CVE-2025-40117
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2025
Last modified:
12/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
misc: pci_endpoint_test: Fix array underflow in pci_endpoint_test_ioctl()<br />
<br />
Commit eefb83790a0d ("misc: pci_endpoint_test: Add doorbell test case")<br />
added NO_BAR (-1) to the pci_barno enum which, in practical terms,<br />
changes the enum from an unsigned int to a signed int. If the user<br />
passes a negative number in pci_endpoint_test_ioctl() then it results in<br />
an array underflow in pci_endpoint_test_bar().



