CVE-2025-40050
Published: Oct 28, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Skip scalar adjustment for BPF_NEG if dst is a pointer In check_alu_op(), the verifier currently calls check_reg_arg() and adjust_scalar_min_max_vals() unconditionally for BPF_NEG operations. However, if the destination register holds a pointer, these scalar adjustments are unnecessary and potentially incorrect. This patch adds a check to skip the adjustment logic when the destination register contains a pointer.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected aced132599b3c8884c050218d4c48eef203678f6 - < b9ef4963227246b9222e1559ddeec8e7af63e6c6affected aced132599b3c8884c050218d4c48eef203678f6 - < 34904582b502a86fdb4d7984b12cacd2faabbe0d |
Linux | Linux | affected 6.17unaffected 0 - < 6.17unaffected 6.17.3 - <= 6.17.*unaffected 6.18 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now