CNNVD-202510-2614 Information

CNNVD ID

CNNVD-202510-2614

CVE-2025-40008

  • CNNVD Published: 2025-10-20

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于kmsan_internal_set_shadow_origin函数中存在越界访问阴影内存的问题,可能导致内核崩溃。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. There is a security loophole in Linux Kernel, which stems from the problem of cross-border access shading in the kmsan international set shadow origin function, which could lead to a kernel collapse.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-10-20

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/e6684ed39edc35401a3341f85b1ab50a6f89a45d https://git.kernel.org/stable/c/5855792c6bb9a825607845db3feaddaff0414ec3 https://git.kernel.org/stable/c/df1fa034c0fc229a63d01ffb20bb919b839cb576 https://git.kernel.org/stable/c/85e1ff61060a765d91ee62dc5606d4d547d9d105 https://git.kernel.org/stable/c/f84e48707051812289b6c2684d4df2daa9d3bfbc https://vigilance.fr/vulnerability/Linux-kernel-multiple-vulnerabilities-dated-21-10-2025-48533

Patch

https://git.kernel.org/stable/c/5855792c6bb9a825607845db3feaddaff0414ec3

Share on: