CVE Database
/

CVE-2025-40031

Back to search

CVE-2025-40031

Published: Oct 28, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: tee: fix register_shm_helper() In register_shm_helper(), fix incorrect error handling for a call to iov_iter_extract_pages(). A case is missing for when iov_iter_extract_pages() only got some pages and return a number larger than 0, but not the requested amount. This fixes a possible NULL pointer dereference following a bad input from ioctl(TEE_IOC_SHM_REGISTER) where parts of the buffer isn't mapped.

VendorProductVersions

Linux

Linux

affected
7bdee41575919773818e525ea19e54eb817770af - < 9338093db954918558677a468d32e77041c65167
affected
7bdee41575919773818e525ea19e54eb817770af - < 6a7874ab814ce12003c46a92f7afc9b035c8e8e9
affected
7bdee41575919773818e525ea19e54eb817770af - < d5cf5b37064b1699d946e8b7ab4ac7d7d101814c

Linux

Linux

affected
6.8
unaffected
0 - < 6.8
unaffected
6.12.53 - <= 6.12.*
unaffected
6.17.3 - <= 6.17.*
unaffected
6.18 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now