#VU117401 Out-of-bounds read in Linux kernel - CVE-2025-40008
Published: October 21, 2025
Vulnerability identifier: #VU117401
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-40008
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the DEFINE_TEST_MEMSETXX() function in mm/kmsan/kmsan_test.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/5855792c6bb9a825607845db3feaddaff0414ec3
- https://git.kernel.org/stable/c/85e1ff61060a765d91ee62dc5606d4d547d9d105
- https://git.kernel.org/stable/c/df1fa034c0fc229a63d01ffb20bb919b839cb576
- https://git.kernel.org/stable/c/e6684ed39edc35401a3341f85b1ab50a6f89a45d
- https://git.kernel.org/stable/c/f84e48707051812289b6c2684d4df2daa9d3bfbc