CVE-2025-40019 — Out-of-bounds Write in Linux
Severity
7.8HIGHOSV
OSV4.7OSV3.2
No vectorEPSS
0.0%
top 92.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: essiv - Check ssize for decryption and in-place encryption
Move the ssize check to the start in essiv_aead_crypt so that
it's also checked for decryption and in-place encryption.