cbcvebase.
CVE-2025-40024
published 2025-10-24

CVE-2025-40024: In the Linux kernel, the following vulnerability has been resolved: vhost: Take a reference on the task in struct vhost_task. vhost_task_create() creates a…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved: vhost: Take a reference on the task in struct vhost_task. vhost_task_create() creates a task and keeps a reference to its task_struct. That task may exit early via a signal and its task_struct will be released. A pending vhost_task_wake() will then attempt to wake the task and access a task_struct which is no longer there. Acquire a reference on the task_struct while creating the thread and release the reference while the struct vhost_task itself is removed. If the task exits early due to a signal, then the vhost_task_wake() will still access a valid task_struct. The wake is safe and will be skipped in this case.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.10-1 (forky)linux 6.16.10-1 (forky)
linuxlinux
linuxlinux>= f9010dbdce911ee1f1af1398a24b1f9f992e0080 < 82a1463c968b1a6ae598a4f2fcef17b71bb7d3a082a1463c968b1a6ae598a4f2fcef17b71bb7d3a0
linuxlinux>= f9010dbdce911ee1f1af1398a24b1f9f992e0080 < d2be773a92874a070215b51b730cb2b1eaa8fae2d2be773a92874a070215b51b730cb2b1eaa8fae2
linuxlinux>= f9010dbdce911ee1f1af1398a24b1f9f992e0080 < 7ce635b3d3aba43296b62b5a2d97c008bc51cbd27ce635b3d3aba43296b62b5a2d97c008bc51cbd2
linuxlinux>= f9010dbdce911ee1f1af1398a24b1f9f992e0080 < afe16653e05db07d658b55245c7a2e0603f136c0afe16653e05db07d658b55245c7a2e0603f136c0
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.13.0 < 6.16.106.16.10
linuxlinux_kernel>= 6.4.0 < 6.6.1096.6.109
linuxlinux_kernel>= 6.7.0 < 6.12.506.12.50
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_redhat6.7MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.