SB2025111331 - Input validation error in Linux kernel platforms iss
Published: November 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-40193)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the proc_read_simdisk() function in arch/xtensa/platforms/iss/simdisk.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/151bd88859474cdaccc1e4c8b21fbf72dbba2ab4
- https://git.kernel.org/stable/c/5d5f08fd0cd970184376bee07d59f635c8403f63
- https://git.kernel.org/stable/c/a0c2c36d864ef3676b05cfd8c58b72ee3214cb1a
- https://git.kernel.org/stable/c/d381de7fd4cdc928ede96987dc64b133e6480dd6
- https://git.kernel.org/stable/c/f40405ccfb87b71175f2d5d004c0b8a0aebcc2cf