CVE Database
/

CVE-2025-40266

Back to search

CVE-2025-40266

Published: Dec 4, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.

VendorProductVersions

Linux

Linux

affected
6211753fdfd05af9e08f54c8d0ba3ee516034878 - < fc3139d9f4c1fe1c7d5f25f99676bd8e9c6a1041
affected
6211753fdfd05af9e08f54c8d0ba3ee516034878 - < bc1909ef38788f2ee3d8011d70bf029948433051
affected
6211753fdfd05af9e08f54c8d0ba3ee516034878 - < f9f1aed6c8a3427900da3121e1868124854569c3
affected
6211753fdfd05af9e08f54c8d0ba3ee516034878 - < 103e17aac09cdd358133f9e00998b75d6c1f1518

Linux

Linux

affected
3.11
unaffected
0 - < 3.11
unaffected
6.6.118 - <= 6.6.*
unaffected
6.12.60 - <= 6.12.*
unaffected
6.17.10 - <= 6.17.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-40266 - Security Vulnerability | QwikSec