SB2025102883 - Memory leak in Linux kernel input misc driver
Published: October 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-40035)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the uinput_ff_upload_to_user() function in drivers/input/misc/uinput.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/48c96b7e9e03516936d6deba54b5553097eae817
- https://git.kernel.org/stable/c/933b87c4590b42500299f00ff55f555903056803
- https://git.kernel.org/stable/c/d3366a04770eea807f2826cbdb96934dd8c9bf79
- https://git.kernel.org/stable/c/e63aade22a33e77b93c98c9f02db504d897a76b4
- https://git.kernel.org/stable/c/f5e1f3b85aadce74268c46676772c3e9fa79897e
- https://git.kernel.org/stable/c/fd8a23ecbc602d00e47b27f20b07350867d0ebe5