CVE-2025-40364
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/04/2025
Last modified:
17/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
io_uring: fix io_req_prep_async with provided buffers<br />
<br />
io_req_prep_async() can import provided buffers, commit the ring state<br />
by giving up on that before, it&#39;ll be reimported later if needed.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.19 (including) | 6.1.129 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.78 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.13.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/233b210a678bddf8b49b02a070074a52b87e6d43
- https://git.kernel.org/stable/c/35ae7910c349fb3c60439992e2e0e79061e95382
- https://git.kernel.org/stable/c/a1b17713b32c75a90132ea2f92b1257f3bbc20f3
- https://git.kernel.org/stable/c/a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
- https://git.kernel.org/stable/c/b86f1d51731e621e83305dc9564ae14c9ef752bf
- https://git.kernel.org/stable/c/d63b0e8a628e62ca85a0f7915230186bb92f8bb4
- https://git.kernel.org/stable/c/f0ef94553868d07c1b14d7743a7e2553e5a831a3



