CVE-2025-40004 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux
15 documents6 sources
Severity
—N/A
No vectorEPSS
0.0%
top 92.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 20
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
net/9p: Fix buffer overflow in USB transport layer
A buffer overflow vulnerability exists in the USB 9pfs transport layer
where inconsistent size validation between packet header parsing and
actual data copying allows a malicious USB host to overflow heap buffers.
The issue occurs because:
- usb9pfs_rx_header() validates only the declared size in packet header
- usb9pfs_rx_complete() uses req->actual (actual received bytes) f…
Affected Packages5 packages
▶CVEListV5linux/linuxa3be076dc174d9022a71a12554feb4c97b5c4d5c — 0da18d49f874d444ad83c8a546fa33bfcf2f582c+3