SB2025102137 - Out-of-bounds read in Linux kernel kmsan
Published: October 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2025-40008)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the DEFINE_TEST_MEMSETXX() function in mm/kmsan/kmsan_test.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5855792c6bb9a825607845db3feaddaff0414ec3
- https://git.kernel.org/stable/c/85e1ff61060a765d91ee62dc5606d4d547d9d105
- https://git.kernel.org/stable/c/df1fa034c0fc229a63d01ffb20bb919b839cb576
- https://git.kernel.org/stable/c/e6684ed39edc35401a3341f85b1ab50a6f89a45d
- https://git.kernel.org/stable/c/f84e48707051812289b6c2684d4df2daa9d3bfbc