CVE-2025-40267
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2025
Last modified:
06/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
io_uring/rw: ensure allocated iovec gets cleared for early failure<br />
<br />
A previous commit reused the recyling infrastructure for early cleanup,<br />
but this is not enough for the case where our internal caches have<br />
overflowed. If this happens, then the allocated iovec can get leaked if<br />
the request is also aborted early.<br />
<br />
Reinstate the previous forced free of the iovec for that situation.



