CVE-2025-40031 — NULL Pointer Dereference in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 93.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
tee: fix register_shm_helper()
In register_shm_helper(), fix incorrect error handling for a call to
iov_iter_extract_pages(). A case is missing for when
iov_iter_extract_pages() only got some pages and return a number larger
than 0, but not the requested amount.
This fixes a possible NULL pointer dereference following a bad input from
ioctl(TEE_IOC_SHM_REGISTER) where parts of the buffer isn't mapped.
Affected Packages5 packages
▶CVEListV5linux/linux7bdee41575919773818e525ea19e54eb817770af — 9338093db954918558677a468d32e77041c65167+3