CNNVD-202510-3838 Information

CNNVD ID

CNNVD-202510-3838

CVE-2025-40081

  • CNNVD Published: 2025-10-28

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未将nr_pages转换为unsigned long类型,可能导致PERF_IDX2OFF函数溢出。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. Linux Kernel has a security loophole, which stems from the failure to convert nr pages to unsigned long, which may result in a spill over the PERF IDX2OF function.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-10-28

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/1a19ba8e1f4ff24ece8ca69b79df8442c431db90 https://git.kernel.org/stable/c/5d01f2b81568289443d22f1e13a363f829de6343 https://git.kernel.org/stable/c/379cae2cb982f571cda9493ac573ab71125fd299 https://git.kernel.org/stable/c/a29fea30dd93da16652930162b177941abd8c75e https://git.kernel.org/stable/c/7500384d3c9587593d75ded3b006835e7aa73ef8 https://git.kernel.org/stable/c/e516cfd19b0f4c774a57b17fb43a7f41991f0735 https://vigilance.fr/vulnerability/Linux-kernel-multiple-vulnerabilities-dated-28-10-2025-48601

Patch

https://www.kernel.org/

Share on: