CVE-2025-40031
Published: Oct 28, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: tee: fix register_shm_helper() In register_shm_helper(), fix incorrect error handling for a call to iov_iter_extract_pages(). A case is missing for when iov_iter_extract_pages() only got some pages and return a number larger than 0, but not the requested amount. This fixes a possible NULL pointer dereference following a bad input from ioctl(TEE_IOC_SHM_REGISTER) where parts of the buffer isn't mapped.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 7bdee41575919773818e525ea19e54eb817770af - < 9338093db954918558677a468d32e77041c65167affected 7bdee41575919773818e525ea19e54eb817770af - < 6a7874ab814ce12003c46a92f7afc9b035c8e8e9affected 7bdee41575919773818e525ea19e54eb817770af - < d5cf5b37064b1699d946e8b7ab4ac7d7d101814c |
Linux | Linux | affected 6.8unaffected 0 - < 6.8unaffected 6.12.53 - <= 6.12.*unaffected 6.17.3 - <= 6.17.*unaffected 6.18 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now