CVE Database
/

CVE-2025-40291

Back to search

CVE-2025-40291

Published: Dec 8, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix regbuf vector size truncation There is a report of io_estimate_bvec_size() truncating the calculated number of segments that leads to corruption issues. Check it doesn't overflow "int"s used later. Rough but simple, can be improved on top.

VendorProductVersions

Linux

Linux

affected
9ef4cbbcb4ac3786a1a4164507511b76b2a572c5 - < 826ce37a842633efe1bb763e4b13045d74060d72
affected
9ef4cbbcb4ac3786a1a4164507511b76b2a572c5 - < 146eb58629f45f8297e83d69e64d4eea4b28d972

Linux

Linux

affected
6.15
unaffected
0 - < 6.15
unaffected
6.17.8 - <= 6.17.*
unaffected
6.18 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now