cbcvebase.
CVE-2025-40019
published 2025-10-24

CVE-2025-40019: In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to…

PriorityP421high7.8
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < 29294dd6f1e7acf527255fb136ffde6602c3a12929294dd6f1e7acf527255fb136ffde6602c3a129
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < 71f03f8f72d9c70ffba76980e78b38c180e6158971f03f8f72d9c70ffba76980e78b38c180e61589
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < df58651968f82344a0ed2afdafd20ecfc55ff548df58651968f82344a0ed2afdafd20ecfc55ff548
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < 248ff2797ff52a8cbf86507f9583437443bf7685248ff2797ff52a8cbf86507f9583437443bf7685
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < f37e7860dc5e94c70b4a3e38a5809181310ea9acf37e7860dc5e94c70b4a3e38a5809181310ea9ac
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < dc4c854a5e7453c465fa73b153eba4ef2a240abedc4c854a5e7453c465fa73b153eba4ef2a240abe
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < da7afb01ba05577ba3629f7f4824205550644986da7afb01ba05577ba3629f7f4824205550644986
linuxlinux>= be1eb7f78aa8fbe34779c56c266ccd0364604e71 < 6bb73db6948c2de23e407fe1b7ef94bf02b7529f6bb73db6948c2de23e407fe1b7ef94bf02b7529f
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-168.1785.15.0-168.178
linuxlinux_kernel>= 0 < 6.8.0-94.966.8.0-94.96
linuxlinux_kernel>= 0 < 6.17.0-12.126.17.0-12.12
linuxlinux_kernel>= 0 < 5.4.0-225.2455.4.0-225.245
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1576.1.157
linuxlinux_kernel>= 5.4.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
linuxlinux_kernel>= 6.2.0 < 6.6.1136.6.113

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat6.1MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.